deal-red-flags

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs local text analysis on provided sales notes. It does not initiate network connections, download external code, or access sensitive system configuration files. The instructions focus on structured analysis and evidence-based reporting.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied data, including call notes, activity logs, and email threads (SKILL.md, Intake section).
  • Ingestion points: Raw call notes, CRM logs, email threads, and transcript excerpts provided by the user.
  • Boundary markers: The instructions do not mandate the use of delimiters for the ingested notes, which is a common defense against prompt injection.
  • Capability inventory: The skill is limited to text analysis and report generation. It does not include tools for network access, file modification, or shell command execution.
  • Sanitization: There are no explicit instructions to sanitize or escape the contents of the ingested deal notes before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — deal-red-flags