sales-happyscribe
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes a persistent learning mechanism via
references/learnings.mdwhich creates a surface for indirect prompt injection. - Ingestion points: The agent is instructed in Step 1 to read
references/learnings.mdat the beginning of the interaction to gain context from previous sessions. - Boundary markers: The skill does not implement delimiters or specific instructions to disregard potentially malicious content found within the learning file.
- Capability inventory: The skill primarily functions as a documentation assistant and router; it does not contain tools for system modification or sensitive data exfiltration that would significantly amplify this risk.
- Sanitization: There are no instructions or mechanisms provided to sanitize or validate the user-influenced content that the agent appends to the
learnings.mdfile in Step 4.
Audit Metadata