icp-builder
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on business strategy and go-to-market methodology. It provides instructions on using frameworks like GAP and SPICED to analyze customer data.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data sources such as CRM records and customer meeting transcripts. While this represents a surface for indirect prompt injection (where instructions could be embedded in transcripts), the skill does not include any high-risk capabilities like arbitrary command execution or network exfiltration of sensitive files, and the current usage is limited to document analysis and synthesis.
- Ingestion points: SKILL.md (Mode 1 and Mode 2) processes client ICP documents, call notes, transcripts, and CRM data.
- Boundary markers: Absent. The skill does not define specific delimiters for untrusted data.
- Capability inventory: The skill performs analysis and text generation. No dangerous subprocesses or system-level tools are utilized.
- Sanitization: Absent. Content is processed as provided by the user.
Audit Metadata