sales-discovery-and-objection-handling
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, which creates a vulnerability surface for indirect prompt injection attacks where instructions hidden in the data could override the agent's behavior.\n
- Ingestion points: As defined in the Inputs section of SKILL.md, the skill requires 'brief, known stakeholders, decision process, assumptions, objections' from external sources.\n
- Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when processing these artefacts, increasing the risk of the agent following malicious content within the data.\n
- Capability inventory: The Capability Contract allows the agent to inspect evidence and edit a 'working copy,' providing a potential vector for data manipulation if an injection succeeds.\n
- Sanitization: The workflow lacks specific steps for sanitizing, validating, or filtering input data before interpolation into the agent's context.
Audit Metadata