skills/erphq/skills/commissions/Gen Agent Trust Hub

commissions

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely documentation-based, providing guidelines for setting up and maintaining commission plans. It does not contain any executable scripts, command line operations, or network requests.- [DATA_EXFILTRATION]: The skill describes an agent workflow that interacts with sensitive data sources, including CRM systems for deal information, HR systems for employee data, and payroll providers (e.g., Gusto, Rippling, ADP) for payment execution. This high-privilege context is appropriate for the skill's stated purpose.- [PROMPT_INJECTION]: The documentation identifies a surface for indirect prompt injection by processing external untrusted data such as deal records and employee disputes.
  • Ingestion points: CRM deal data, HR representative records, and employee dispute submissions in the dispute resolution workflow.
  • Boundary markers: None are specified in the instructional text.
  • Capability inventory: Reading from CRM/HR APIs and writing to payroll systems or generating external reports.
  • Sanitization: No explicit data sanitization or validation steps are outlined for the incoming deal or dispute data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — commissions