sales-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied deal records in CSV or Markdown formats, creating an attack surface for instructions embedded within the data fields.
- Ingestion points: The skill operates on deal spreadsheets, CSV files, and Markdown tables provided by the user (as described in
SKILL.md). - Boundary markers: The skill relies on the structured format as an implicit boundary but lacks specific instructions to the agent to disregard natural language instructions embedded within the data fields.
- Capability inventory: The skill utilizes a shell script (
scripts/verify.sh) for data validation and requests the agent to perform data cleaning, weighted forecasting, and follow-up generation. - Sanitization: The validation script performs structural and arithmetic checks but does not include sanitization or filtering to detect or prevent prompt injection attempts within text-based fields.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local bash script for linting and verification purposes.
- Evidence:
SKILL.mdcontains instructions to runscripts/verify.shon pipeline files. The script is provided within the skill package and performs read-only analysis using standard system utilities like awk, grep, and sed.
Audit Metadata