revenue-kpi-framework

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external business data through an interactive workflow to design KPI hierarchies and metric trees. This input is processed and can be persisted if the agent platform supports memory features.\n
  • Ingestion points: User-provided business details and metric values captured during the ## Interview phase defined in SKILL.md.\n
  • Boundary markers: The skill does not define specific delimiters (e.g., XML tags or unique markers) to isolate user input from the agent's internal logic.\n
  • Capability inventory: The skill is restricted to text generation. It does not utilize shell execution, network communication, or file system access tools.\n
  • Sanitization: No procedures are present to sanitize, escape, or validate user-provided data before it is incorporated into the prompt context.\n- [NO_CODE]: The skill is composed entirely of Markdown and YAML instructions. It does not include scripts, binaries, or automated execution commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:18 PM
Security Audit — agent-trust-hub — revenue-kpi-framework