competitive-objection-response

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted external data, creating an indirect prompt injection surface.
  • Ingestion points: The skill retrieves data from customer-call intelligence, CRM opportunity data, and exact buyer wording from calls, notes, or user messages as defined in references/CONTEXT.md and SKILL.md.
  • Boundary markers: The instructions in SKILL.md and references/INTERNAL.md require the agent to clearly label, quote, and attribute buyer wording and paraphrases, providing a structural distinction between data and instructions.
  • Capability inventory: The skill utilizes read-only market intelligence tools and generates textual response artifacts. It does not demonstrate capabilities for arbitrary command execution or privilege escalation.
  • Sanitization: While the methodology emphasizes honesty and evidence density, there is no explicit instruction for technical sanitization of untrusted input before interpolation into the response template.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:04 PM
Security Audit — agent-trust-hub — competitive-objection-response