sales-revenue
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to read an external file,
.agents/marketing-context.md, which creates a surface for indirect prompt injection if that file contains untrusted content. - Ingestion points: The agent reads from
.agents/marketing-context.md(SKILL.md). - Boundary markers: The instructions lack explicit delimiters or safety warnings to ignore instructions found within the context file.
- Capability inventory: The skill outlines activities involving CRM automation, lead routing, and enrichment, which could be exploited if an injection occurs.
- Sanitization: There is no evidence of content sanitization or validation for the ingested data.
Audit Metadata