workflow-gtm
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions and does not include any scripts, external dependencies, or remote code patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for untrusted data from user interviews and analytics tools. 1. Ingestion points: Step 1 (inventory/interview) and Step 2 (funnel metrics). 2. Boundary markers: Absent. 3. Capability inventory: Coordination of other skills and generation of a markdown scorecard report. 4. Sanitization: Absent. The inclusion of human approval gates between planning and execution is a strong security best practice that mitigates risks from embedded instructions.
Audit Metadata