sales-revenue

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to read an external file, .agents/marketing-context.md, which creates a surface for indirect prompt injection if that file contains untrusted content.
  • Ingestion points: The agent reads from .agents/marketing-context.md (SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or safety warnings to ignore instructions found within the context file.
  • Capability inventory: The skill outlines activities involving CRM automation, lead routing, and enrichment, which could be exploited if an injection occurs.
  • Sanitization: There is no evidence of content sanitization or validation for the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:55 AM
Security Audit — agent-trust-hub — sales-revenue