business-growth-skills
Warn
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to download additional components from a remote GitHub repository (
alirezarezvani/claude-skills) using thenpx agent-skills-clicommand.- [COMMAND_EXECUTION]: The skill's functionality relies on executing external Python scripts (e.g.,health_score_calculator.py,pipeline_analyzer.py) that are not included in the provided package but are fetched from remote sources.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as RFPs, customer health records, and contract templates. - Ingestion points: Processes data from customer success metrics, RFP documents, and pipeline logs.
- Boundary markers: There are no defined boundary markers or instructions provided to the agent to treat external data as untrusted or to ignore embedded instructions.
- Capability inventory: The skill possesses the capability to execute shell commands via Python scripts.
- Sanitization: No sanitization or validation mechanisms are described for the external data before it is processed by the scripts or the agent.
Audit Metadata