challenger-sale
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill features a surface for indirect prompt injection by encouraging users to provide their own data (product names, buyer roles, differentiators) for the agent to process into sales pitches.
- Ingestion points: User-supplied parameters in the "How to Use" and "Checklists & Templates" sections of SKILL.md.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious content within these inputs.
- Capability inventory: The skill lacks dangerous capabilities such as file system writes, network requests, or shell execution tools, neutralizing the impact of potential injections.
- Sanitization: No input validation or sanitization logic is present.
- [METADATA_POISONING]: The
Skill Boundariessection contains text that is entirely unrelated to sales, instead referencing "audio production workflows" and "audio engineering expertise." This appears to be a copy-paste error from a different skill template. While this makes the metadata misleading, it does not facilitate any security bypass or malicious behavior.
Audit Metadata