sales-deal-room
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses a persistent file (
references/learnings.md) to store and retrieve insights across sessions, which creates a surface for indirect prompt injection. - Ingestion points:
references/learnings.mdis read at the beginning of the workflow in Step 1. - Boundary markers: The skill lacks delimiters or protective instructions when reading the stored learnings.
- Capability inventory: The skill is a creative writing and design assistant with no autonomous execution tools.
- Sanitization: No sanitization is performed on data written to or read from the learnings file.
- [COMMAND_EXECUTION]: The documentation provides an example
curlcommand to assist the user in setting up webhooks with the Qwilr API. This is intended as a static reference for the user and does not involve automated execution by the agent.
Audit Metadata