stoic-negotiator
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to ingest data from user-provided documents and external web research, which can serve as a vector for instructions intended to influence the agent's behavior.
- Ingestion points: In
SKILL.md, the workflow includes instructions to "attach documents" and execute a "research loop" using external tools to fetch market data and precedents. - Boundary markers: There are no specific technical delimiters (such as XML tags or unique markers) mandated in the instructions to isolate external content from system prompts, although the agent is instructed to read back a "negotiation state summary" to the user for verification.
- Capability inventory: The skill possesses the ability to generate negotiation scripts, prioritized counteroffer packages, and messages intended for external communication.
- Sanitization: The skill provides mitigation by requiring "explicit human approval for binding language or external actions" and mandating that the agent "always ask permission before sharing confidential user data externally."
- Handling of High-Value Financial Data: The skill is designed to process sensitive negotiation details including compensation, pricing, and contract terms.
- Context: The instructions explicitly direct the agent to "validate what information the user is comfortable sharing" and to distinguish between confirmed facts and assumptions, which helps manage the risk of unauthorized data exposure.
Audit Metadata