gtm-deal-intel

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it is designed to ingest and process untrusted external data.
  • Ingestion points: Phase 1 (Deal Input) accepts raw call transcripts, email threads, meeting notes, and freeform updates from the user or HubSpot sync files.
  • Boundary markers: The instructions lack explicit requirements for delimiters or instructions to ignore embedded commands within the processed text.
  • Capability inventory: The skill performs extensive file read and write operations within the data/gtm/ directory, creating a risk if malicious instructions in a transcript could influence file content or subsequent agent actions.
  • Sanitization: There is no evidence of sanitization or filtering of the input data before it is structured and saved to JSON files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 10:41 AM
Security Audit — agent-trust-hub — gtm-deal-intel