ops
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted external data, specifically verbatim customer language and prospect problem descriptions, which creates a surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through client intake records (
references/onboarding.md), verbatim buyer phrases (references/product-marketing-template.md), and prospect problem descriptions (references/proposal.md). - Boundary markers: The skill uses Markdown templates and headers to organize data, but it lacks explicit instructions to treat the ingested verbatim text as untrusted or to ignore instructions embedded within that text.
- Capability inventory: The agent has access to highly capable tools including
bash,run_command,write_to_file, andreplace_file_content(defined inSKILL.mdandagents/openai.yaml). - Sanitization: There are no defined mechanisms for sanitizing or escaping the external content before the agent processes it to generate proposals, SOWs, or marketing artifacts.
Audit Metadata