discover-brand
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection due to its core functionality of ingesting and processing data from external, untrusted sources.
- Ingestion points: Content is retrieved from Notion, Confluence, Google Drive, Box, Microsoft 365 (SharePoint/OneDrive), Figma, Gong, Granola, and Slack during the discovery phases.
- Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore or isolate potential commands embedded within the retrieved documents or transcripts.
- Capability inventory: The skill uses the
Tasktool to execute autonomous discovery agents and supports chaining results to a secondary guideline generation skill. - Sanitization: There are no mentioned mechanisms for sanitizing, escaping, or validating the text content extracted from these platforms before it is analyzed by the agent.
Audit Metadata