sales-enablement

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The 'Intake' procedure in SKILL.md requires the agent to ingest buyer language from win/loss reports, sales calls, and competitor teardowns. Additionally, references/playbook.md processes real deal history and case briefs.
  • Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings when processing these external data sources.
  • Capability inventory: The skill is granted high-privilege tools including bash, run_command, and write_to_file as defined in SKILL.md and agents/openai.yaml, which increases the potential impact of a successful injection.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the external content before it is interpolated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — sales-enablement