sales-clari-copilot
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill uses
references/learnings.mdto store and retrieve accumulated knowledge, creating an indirect prompt injection surface where external data could be persisted and re-ingested. 1. Ingestion points:references/learnings.md(read during Step 1). 2. Boundary markers: Absent. 3. Capability inventory: File read and write access to thereferences/directory. 4. Sanitization: Absent. - [EXTERNAL_DOWNLOADS]: The skill mentions installing related tools from the same author (
sales-skills) using thenpxpackage runner.
Audit Metadata