partnerships-kickoff
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external project files to build a long-term context artifact, creating a vector for instructions embedded in those files to influence future agent sessions.
- Ingestion points: Reads file inventory including README, agent-instruction files, partner agreements, and program documents as specified in SKILL.md Section 1.
- Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded prompts when reading these external files.
- Capability inventory: The skill updates the partnerships-context.md file, modifies persistent memory stores, and can optionally patch project-level agent-instruction files.
- Sanitization: Section 6 of SKILL.md provides explicit instructions to exclude PII, contact lists, and negotiated rates from memory, reducing the risk of data exfiltration via shared stores.
Audit Metadata