friday-brief
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external business sources which are ingestion points for potentially untrusted content.
- Ingestion points: The skill retrieves data from external CRM systems (Bitrix24, amoCRM) and payment processors (YuKassa, Tinkoff) as described in the 'Pulse' and 'Sales Analysis' steps.
- Boundary markers: Absent. There are no explicit instructions or delimiters used to separate the external data from the skill's primary instructions or to warn the agent about potential embedded commands.
- Capability inventory: The skill has access to the
Bash,WebFetch, andReadtools, which could be misused if a prompt injection attack is successful. - Sanitization: Absent. There is no evidence of data sanitization or validation performed on the fields retrieved from external systems before they are processed by the agent.
Audit Metadata