gtm-account-segmentation

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
  • Ingestion points: The skill processes user-supplied "account facts" and company evidence to perform segmentation (SKILL.md, references/context.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat input data as non-executable text, which could allow malicious instructions inside account data to influence the agent.
  • Capability inventory: The skill is restricted to reading local files within the ~/.gtm/ directory and lacks network access, file-writing capabilities, or shell execution tools (SKILL.md, references/context.md).
  • Sanitization: No explicit sanitization, escaping, or validation of the external account data is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 03:45 PM
Security Audit — agent-trust-hub — gtm-account-segmentation