skills/erphq/skills/quoting-cpq/Gen Agent Trust Hub

quoting-cpq

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown documentation describing a business process. No executable code or commands are present.- [PROMPT_INJECTION]: The skill describes an agent workflow that processes external data from CRM systems and customer documents. While this defines an attack surface for indirect prompt injection, no malicious triggers or unsafe interpolation patterns were found in the static instructions.
  • Ingestion points: CRM opportunity records and customer-provided MSA files (SKILL.md).
  • Boundary markers: Not specified.
  • Capability inventory: Document generation and API interactions with e-signature platforms (DocuSign).
  • Sanitization: Not specified.- [NO_CODE]: The file analyzed contains only markdown text and metadata; it does not include any scripts, shell commands, or executable logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — quoting-cpq