build-business-case

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • Indirect Prompt Injection Surface: The skill processes external data including public research, transcripts, and web links (Ingestion Points: SKILL.md, references/workflow.md). While the skill lacks explicit boundary markers for this data, it implements a strict evidence hierarchy to prioritize internal metrics. The capabilities are limited to text generation and guided system updates (Capability Inventory: text artifacts, CRM/document updates upon request). No specific sanitization methods for external content are documented, but the focus on source labeling and user review acts as a mitigation.
  • Human-in-the-Loop Review: The skill includes explicit instructions to avoid performing sensitive actions, such as updating records or sharing documents, until the user provides review and authorization. This ensures that the agent does not act autonomously on potentially untrusted instructions embedded in external data.
  • Evidence Integrity: The workflow mandates distinguishing between 'Known', 'Inferred', and 'Assumed' data. This practice ensures that external strategic language is not conflated with verified customer proof, maintaining the reliability of the business case.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 09:18 AM
Security Audit — agent-trust-hub — build-business-case