sales-coaching
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of instructional Markdown and metadata; it does not include any Python scripts, JavaScript files, or binary executables.
- [PROMPT_INJECTION]: The skill's workflow establishes a surface for indirect prompt injection because it is designed to ingest and process raw, untrusted data from external prospects.
- Ingestion points: The agent is instructed to pull raw text from email replies and call transcripts in 'Step 1: Collect Sales Data'.
- Boundary markers: The instructions do not provide the agent with specific delimiters or warnings to ignore instructions embedded within the prospect-provided text.
- Capability inventory: The skill requires the agent to utilize tools for accessing communication platforms and CRMs (e.g., Salesforce, HubSpot, Gong).
- Sanitization: There are no explicit instructions for the agent to sanitize or validate the content of the data fetched from external sources.
Audit Metadata