proposal-writing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute directory listing commands (ls) on local storage paths (such as ~/.claude/skills/) to identify which companion skills are installed. This information is used to provide the user with installation recommendations for missing related tools.
  • [EXTERNAL_DOWNLOADS]: Documentation within the skill suggests the installation of additional sales-related components using the npx skills add command, which pulls content from the developer's organizational repository.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill is designed to ingest and process untrusted external business documents, including RFPs, RFQs, and SOWs, which are provided by the user.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the content being analyzed.
  • Capability inventory: The agent maintains capabilities for shell command execution and local file reads.
  • Sanitization: There are no explicit sanitization or filtering steps defined for the external data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — proposal-writing