proposal-generation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions and examples describe workflows that ingest untrusted external data, such as prospect account statements, tax returns, and CSV files, creating a surface for indirect prompt injection.\n
  • Ingestion points: Data imports from prospects, CSV holdings lists, and account aggregation tools like Plaid and Yodlee mentioned in SKILL.md.\n
  • Boundary markers: None specified in the instructions to prevent the agent from executing instructions embedded in processed data.\n
  • Capability inventory: The skill outlines interactions with CRMs (Salesforce), document generation templates, and portfolio management platforms (Orion) as seen in SKILL.md and references/examples.md.\n
  • Sanitization: No data validation or sanitization procedures are defined for the imported financial data.\n- [SAFE]: The skill references several well-known financial technology platforms and services, including Orion, Black Diamond, Nitrogen, MoneyGuidePro, RightCapital, Advyzon, Salesforce, Schwab, Plaid, and Yodlee. These references are appropriate for the skill's intended use case and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:25 AM
Security Audit — agent-trust-hub — proposal-generation