challenger-sale

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill features a surface for indirect prompt injection by encouraging users to provide their own data (product names, buyer roles, differentiators) for the agent to process into sales pitches.
  • Ingestion points: User-supplied parameters in the "How to Use" and "Checklists & Templates" sections of SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious content within these inputs.
  • Capability inventory: The skill lacks dangerous capabilities such as file system writes, network requests, or shell execution tools, neutralizing the impact of potential injections.
  • Sanitization: No input validation or sanitization logic is present.
  • [METADATA_POISONING]: The Skill Boundaries section contains text that is entirely unrelated to sales, instead referencing "audio production workflows" and "audio engineering expertise." This appears to be a copy-paste error from a different skill template. While this makes the metadata misleading, it does not facilitate any security bypass or malicious behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:26 PM
Security Audit — agent-trust-hub — challenger-sale