plan-deal-strategy

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [Data Access and Scoping]: The skill interacts with sensitive business data categories including CRM, meeting notes, and internal messaging. This access is governed by a mandatory preflight step that resolves sources and applies operational obligations, ensuring that data usage remains within the user's intended context.
  • [Indirect Prompt Injection Consideration]: Because the skill processes untrusted external data like meeting transcripts and customer emails, it is exposed to potential indirect prompt injection. The skill mitigates this by instructing the agent to clearly separate evidence from inference, cite sources with stable links, and require explicit user approval before performing any write actions in external systems.
  • [Execution Environment]: The skill consists entirely of instructional markdown and configuration schemas. It does not include executable scripts, shell commands, or external package dependencies, significantly reducing the potential for traditional code-based exploits or privilege escalation.
  • [Integrity and Grounding]: The instructions place a high priority on data integrity, specifically requiring CRM data to be the authoritative source for deal metadata and forbidding the fabrication of stakeholders or deal facts. This focus on grounding helps prevent the generation of misleading or hallucinated sales information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 02:40 AM
Security Audit — agent-trust-hub — plan-deal-strategy