client-proposal-generator
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is designed for professional document generation and follows a structured workflow without any malicious instructions or hidden behaviors. It correctly manages client information and adheres to its stated purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface through web research, which is a common vulnerability for indirect prompt injection where instructions could be hidden on external websites.
- Ingestion points: Client research results from WebSearch and Bash (references/research.md).
- Boundary markers: Not explicitly defined in the instructions for isolating external content.
- Capability inventory: The skill has access to Bash for system commands and Write for file creation (SKILL.md).
- Sanitization: There is no explicit sanitization or filtering logic applied to the external content before it is used for personalization in the final document.
Audit Metadata