pricing-change-strategist
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting data from external billing and CRM platforms and using it within the agent context alongside high-capability tools. * Ingestion points: The skill reads pricing, revenue, and churn data from billing systems such as Stripe, Mercury, and Supabase. * Boundary markers: Absent; the instructions rely on natural language guidance rather than technical delimiters or strict schema validation to separate external data from the system prompt. * Capability inventory: The skill is authorized to use Bash, WebFetch, WebSearch, Write, and Agent tools, which could be leveraged if malicious instructions were embedded in the ingested billing data. * Sanitization: The skill does not specify any sanitization, filtering, or validation steps for the data retrieved from external APIs or databases.
Audit Metadata