co-selling-strategy

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from two main untrusted sources: user responses during the co-sell strategy interview and content from external websites audited by the agent during the design phase (SKILL.md). This creates a surface for indirect prompt injection where malicious instructions could be embedded in the audited pages.\n
  • Ingestion points: User-provided interview answers and content from external deal-registration or partner pages.\n
  • Boundary markers: No explicit instructions or delimiters are used to separate ingested content from system-level instructions.\n
  • Capability inventory: The skill utilizes web browsing tools and persistent memory to store and manage charter decisions.\n
  • Sanitization: No specific sanitization or filtering logic is implemented for external data.\n- [EXTERNAL_DOWNLOADS]: The skill references several external business logic modules (e.g., mbfinotti/partnerships-skills@partner-channel-conflict) for specialized functions like conflict adjudication and joint GTM planning. These are official resources from the skill's own author (mbfinotti) and represent standard modular design.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — co-selling-strategy