pricing-strategy
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user input regarding business value and customer segments without explicit boundary markers or sanitization instructions, creating a surface for indirect prompt injection.
- Ingestion points: User responses to the coaching prompts in
SKILL.md, where the user is asked to describe outcomes and customer metrics. - Boundary markers: The instructions lack explicit delimiters or instructions for the agent to ignore potentially malicious instructions embedded within the user-provided data.
- Capability inventory: The skill logic is purely informational and does not invoke external tools, shell commands, or network operations, which limits the potential impact of an injection.
- Sanitization: No explicit sanitization or filtering logic is defined for the ingested user content.
- [SAFE]: The skill correctly references external sources and case studies from established academic, news, and technology platforms.
- The skill identifies and links to documentation from well-known services and organizations, including OpenAI, Anthropic, Google, and JSTOR.
- The skill references vendor-owned infrastructure at
deciqai.comandgithub.com/deciqaifor metadata and updates, which is standard behavior.
Audit Metadata