competitive-deal-prep
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, specifically customer call transcripts, meeting notes, and email communications, which creates a potential vector for indirect prompt injection.
- Ingestion points: As outlined in SKILL.md and references/CONTEXT.md, the agent retrieves recent call intelligence, meeting notes, and CRM opportunity data for synthesis.
- Boundary markers: The skill partially mitigates this risk by requiring the use of the assets/deal-prep-template.md template, which explicitly separates buyer quotes from internal team assumptions and recorded opportunity states.
- Capability inventory: The skill is configured to use read-only intelligence tools (e.g., list_products, get_report) and does not have the capability to write to the file system or execute arbitrary network requests.
- Sanitization: The instructions do not specify a data sanitization process, relying instead on the language model's safety guardrails and the structured output requirements to prevent execution of malicious instructions found in ingested text.
Audit Metadata