deal-stage-nudges
Fail
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: CRITICALPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from HubSpot deals and engagements, which creates a surface for indirect prompt injection. Content from external actors (such as deal notes or email bodies) could contain hidden instructions intended to bias or override the agent's logic. Evidence Chain:
- Ingestion points: Workflow step 1 ('Pull open deals') and step 3 ('Read recent engagements') in SKILL.md.
- Boundary markers: None; the skill does not define specific delimiters or instructions to ignore embedded content.
- Capability inventory: None; the skill is a markdown file with no scripts, command execution, or network operations.
- Sanitization: None specified for external HubSpot content.
- [PROMPT_INJECTION]: The metadata 'author' field contains the domain 'Builder.org', which was flagged by automated scanners as a malicious URL. While the skill does not include any tools or scripts that interact with this domain via network requests, the presence of a flagged URL in the metadata is noted for supply chain visibility.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata