deal-review
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external opportunity data and stakeholder information to generate updates for a CRM. This creates a surface where malicious content within CRM fields or stakeholder roles could influence agent behavior.
- Ingestion points: External pipeline data, buying committee roles, and influencer documentation (SKILL.md).
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the framework.
- Capability inventory: The skill allows writing committed actions, deadlines, and owners directly into a CRM system.
- Sanitization: No explicit sanitization or validation logic is defined for the external data being processed.
- [NO_CODE]: The skill consists entirely of markdown-based instructions and process templates. No scripts, binaries, or executable code were detected.
Audit Metadata