quoting-cpq
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of markdown documentation describing a business process. No executable code or commands are present.- [PROMPT_INJECTION]: The skill describes an agent workflow that processes external data from CRM systems and customer documents. While this defines an attack surface for indirect prompt injection, no malicious triggers or unsafe interpolation patterns were found in the static instructions.
- Ingestion points: CRM opportunity records and customer-provided MSA files (SKILL.md).
- Boundary markers: Not specified.
- Capability inventory: Document generation and API interactions with e-signature platforms (DocuSign).
- Sanitization: Not specified.- [NO_CODE]: The file analyzed contains only markdown text and metadata; it does not include any scripts, shell commands, or executable logic.
Audit Metadata