sales-enablement
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The 'Intake' procedure in
SKILL.mdrequires the agent to ingest buyer language from win/loss reports, sales calls, and competitor teardowns. Additionally,references/playbook.mdprocesses real deal history and case briefs. - Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings when processing these external data sources.
- Capability inventory: The skill is granted high-privilege tools including
bash,run_command, andwrite_to_fileas defined inSKILL.mdandagents/openai.yaml, which increases the potential impact of a successful injection. - Sanitization: There is no evidence of sanitization, validation, or filtering of the external content before it is interpolated into the agent's context.
Audit Metadata