gtm-trigger-event-outbound

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface as it processes external content from profiles/client-profile.md and user-provided event descriptions. Ingestion points: Local profile configuration and runtime trigger event details. Boundary markers: Not present; the instructions do not define specific delimiters or instructions to ignore potential commands within the ingested data. Capability inventory: The skill instructions include searching CRM data and writing artifacts to disk in Markdown, HTML, and PDF formats. Sanitization: No explicit logic is provided for escaping or validating external content before it is processed.
  • [DYNAMIC_EXECUTION]: The skill mentions an option to generate PDF artifacts using Python and the reportlab library. This dynamic generation is a standard functional component for artifact creation and does not involve the execution of untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 04:20 PM
Security Audit — agent-trust-hub — gtm-trigger-event-outbound