gtm-trigger-event-outbound
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface as it processes external content from
profiles/client-profile.mdand user-provided event descriptions. Ingestion points: Local profile configuration and runtime trigger event details. Boundary markers: Not present; the instructions do not define specific delimiters or instructions to ignore potential commands within the ingested data. Capability inventory: The skill instructions include searching CRM data and writing artifacts to disk in Markdown, HTML, and PDF formats. Sanitization: No explicit logic is provided for escaping or validating external content before it is processed. - [DYNAMIC_EXECUTION]: The skill mentions an option to generate PDF artifacts using Python and the
reportlablibrary. This dynamic generation is a standard functional component for artifact creation and does not involve the execution of untrusted remote code.
Audit Metadata