resonance-sales-lead-ops

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from an external CRM system.
  • Ingestion points: The skill reads lead-related data including contact, company, and deal information, as well as conversation evidence like CRM notes and chat threads (SKILL.md).
  • Boundary markers: There are no instructions for using boundary markers or delimiters to isolate ingested CRM data from the agent's system instructions.
  • Capability inventory: The skill's documented capabilities are limited to data analysis and reporting; no high-risk tools such as shell execution, network requests, or file system writes are utilized.
  • Sanitization: The procedure does not include steps for sanitizing, escaping, or validating the content retrieved from CRM records before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 12:08 AM
Security Audit — agent-trust-hub — resonance-sales-lead-ops