sales-forecast-diagnostic
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data sources, including CRM snapshots, field history, and activity logs.
- Ingestion points: Data is brought into the agent context during the 'Inventory the evidence base' and 'Reconstruct the missed period' steps of the workflow (Workflow Steps 3 and 4).
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when the agent reads this data.
- Capability inventory: The skill encourages the agent to use code execution tools ('If your harness can execute code, script this...') and write analysis reports.
- Sanitization: There are no explicit instructions for the agent to sanitize or escape the content of the CRM logs before processing or interpolating them into diagnostic findings. This creates a surface where adversarial text within a CRM record could theoretically influence the agent's behavior, although the skill's structured diagnostic fingerprints mitigate this risk.
Audit Metadata