sales-market-sizing

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, which creates a surface for indirect prompt injection attacks. Any malicious instructions embedded in user-provided files or web search results could potentially influence the agent's behavior.
  • Ingestion points: Data enters the agent's context through user-provided CRM history, firmographic database exports, and live web search results as outlined in the 'Source the data' section of the instructions.
  • Boundary markers: The instructions do not define clear delimiters or explicitly instruct the model to ignore any embedded directives within the ingested data, increasing the likelihood that the model might obey injected instructions.
  • Capability inventory: The skill contains logic for strategic market planning and mathematical analysis. While it does not explicitly request high-privilege tools like shell access, the absence of an 'allowed-tools' restriction allows the agent to potentially use any tools provided by the platform to act on injected data.
  • Sanitization: There are no specified procedures for validating, filtering, or sanitizing the content retrieved from external sources before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:18 PM
Security Audit — agent-trust-hub — sales-market-sizing