proposals

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's instructions and templates are focused on domain-specific document generation (sales and SOWs). All operations are local to the agent's environment and do not involve sensitive data access or external communications.
  • [COMMAND_EXECUTION]: The skill utilizes a local bash script, scripts/verify.sh, to perform structural linting on generated markdown files. The script uses read-only commands such as grep and awk to check for required sections and word counts. It does not download external content or execute arbitrary commands from untrusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted discovery notes as input for generating proposals. This constitutes an indirect prompt injection surface. However, the skill implements strong mitigation by providing explicit structural rubrics and a verification script that enforces specific document sections, effectively constraining the agent's output to the intended format.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — proposals