sales-fellow
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via its learning feedback loop mechanism.\n
- Ingestion points: The file
references/learnings.mdis read at the start of every session in Step 1 to provide accumulated platform knowledge.\n - Boundary markers: There are no protective delimiters or explicit instructions to the agent to disregard commands embedded within the
learnings.mdcontent.\n - Capability inventory: The skill interprets user meeting data and possesses routing capabilities to other skills, creating a surface where malicious instructions could influence agent workflow.\n
- Sanitization: The skill lacks validation or sanitization processes for content appended to the learning file in Step 4, allowing potentially untrusted data to enter the long-term context.
Audit Metadata