gtm-competitive-displacement

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from CRM records, including account notes, emails, and call transcripts, without explicit sanitization or boundary markers. This attack surface could allow malicious instructions embedded in these external sources to influence the agent's output during sequence generation. Ingestion points: CRM account records, deal stage, notes, emails, and call transcripts (SKILL.md Step 1b). Boundary markers: None identified. Capability inventory: File system write operations for Markdown, HTML, and PDF artifacts, and email sequence generation context (SKILL.md Step 3, Artifact Generation). Sanitization: None identified.\n- [DYNAMIC_EXECUTION]: The skill suggests generating PDF artifacts using Python and the reportlab library. This implies the agent may generate and execute script code at runtime to produce the requested file format. Evidence: Artifact Generation section, Option C (SKILL.md).\n- [COMMAND_EXECUTION]: The workflow involves querying a CRM system to retrieve account and contact information and performing file system operations to read local profile data and write generated sequences. Evidence: Step 1b (Search CRM) and Context section (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 04:19 PM
Security Audit — agent-trust-hub — gtm-competitive-displacement