sales-radar
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows secure design principles, relying on localized reference data for its primary functionality and providing clear instructions for manual verification of external links.
- [PROMPT_INJECTION]: Instructions are strictly scoped to sales resource curation. There are no attempts to override system prompts, bypass safety filters, or implement deceptive role-play scenarios.
- [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were identified. Network activity is limited to verifying the status and identity of publicly available sales resource websites, which is consistent with the skill's intended purpose.
- [OBFUSCATION]: Analysis of all files, including markdown and reference tables, reveals no use of Base64, zero-width characters, homoglyphs, or other encoding techniques intended to hide malicious content.
- [COMMAND_EXECUTION]: The skill does not employ any shell command injection patterns or dynamic context execution placeholders (
!command). It operates entirely within the agent's standard conversational and curatorial context. - [INDIRECT_PROMPT_INJECTION]: Although the skill fetching external URLs to verify freshness presents a potential injection surface, the instructions specifically limit the agent's interaction to identifying dates and brand identities. The absence of dangerous capabilities (such as file writing or code execution) effectively mitigates this risk.
Audit Metadata