sales-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external JSON files, creating an attack surface for indirect prompt injection.\n
- Ingestion points: Data is loaded from user-provided files in
rfp_response_analyzer.py,competitive_matrix_builder.py, andpoc_planner.py.\n - Boundary markers: The scripts do not utilize delimiters or specific instructions to the agent to ignore embedded commands in the ingested text.\n
- Capability inventory: The skill executes local Python scripts for data parsing and reporting.\n
- Sanitization: There is no evidence of input validation or sanitization to prevent the interpolation of malicious instructions into the agent's context.
Audit Metadata