sales-brief
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources such as payment processors and CRM systems, creating a potential vector for indirect prompt injection if those sources contain malicious content.
- Ingestion points: Sales operations are retrieved from
~~платежи, revenue data from~~бухгалтерия, and campaign logs from~~crm. - Boundary markers: The skill does not implement delimiters or explicit warnings to the agent to ignore instructions embedded within the ingested data.
- Capability inventory: The skill is granted access to
Bash,WebFetch, andReadtools, which increases the impact of potential injection. - Sanitization: There is no evidence of sanitization, filtering, or validation of the external business data before it is processed.
Audit Metadata