sales-discovery-questions

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions, templates, and evaluation data. It does not include any executable scripts (Python, Node.js, Shell), hardcoded credentials, or privileged commands. Its functionality is focused on guiding the agent to produce high-quality sales questioning sets.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a standard ingestion surface by instructing the agent to perform web research and process user notes. This is a common pattern for research-oriented skills and is considered safe in this context as the skill lacks any dangerous capabilities that could be exploited via injection.
  • Ingestion points: SKILL.md (Workflow Step 2) instructs the agent to gather context by browsing the web for company and persona research and by reading user notes.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore embedded instructions' prompts for the external research data.
  • Capability inventory: The skill is limited to text generation; it contains no subprocess calls, file system write operations, or custom network exfiltration mechanisms.
  • Sanitization: Absent; there is no defined logic for filtering or validating the ingested external data before it is used to generate the call sheet.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:18 PM
Security Audit — agent-trust-hub — sales-discovery-questions