revenue-leakage

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a specialized set of instructions for revenue analysis that adheres to security best practices. It explicitly defines its scope, establishes clear ground rules for data classification, and includes error-handling mechanisms for common analytical failures. It correctly references sibling skills from the same author as internal resources and uses well-known industry domains for educational reference.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as its core purpose involves processing and reconciling untrusted data from external sources.
  • Ingestion points: The skill ingests CRM stage-change history, owner history, billing and invoice records, and user-provided record samples through various workflow steps and interview questions (SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or ignore potentially malicious instructions embedded within the processed record data.
  • Capability inventory: The skill instructions allow the agent to query external funnel systems directly if the environment provides such tools, which typically requires significant data access permissions (SKILL.md).
  • Sanitization: The skill lacks specific instructions for sanitizing or escaping external content before it is processed or included in the final report output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:18 PM
Security Audit — agent-trust-hub — revenue-leakage