deal-review

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external opportunity data and stakeholder information to generate updates for a CRM. This creates a surface where malicious content within CRM fields or stakeholder roles could influence agent behavior.
  • Ingestion points: External pipeline data, buying committee roles, and influencer documentation (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the framework.
  • Capability inventory: The skill allows writing committed actions, deadlines, and owners directly into a CRM system.
  • Sanitization: No explicit sanitization or validation logic is defined for the external data being processed.
  • [NO_CODE]: The skill consists entirely of markdown-based instructions and process templates. No scripts, binaries, or executable code were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:50 AM
Security Audit — agent-trust-hub — deal-review