pricing-quarterly-review
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests untrusted data from external sources, specifically customer quotes and CRM records.
- Ingestion points: CRM data exports, including "lost-to-price verbatim quotes" and billing system distributions (referenced in the 'Core data pull' and 'Workflow' sections).
- Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" directives to prevent the agent from following malicious commands hidden in the CRM quotes.
- Capability inventory: The skill uses
ReadandWritetools to modify project configuration files (brand-config.json). - Sanitization: There is no evidence of sanitization, filtering, or escaping for the ingested external strings before they are logged or included in the review agenda.
Audit Metadata