sales-hi-ai
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a persistent 'learnings' mechanism that introduces a surface for indirect prompt injection.
- Ingestion points: The agent is instructed in Step 1 to read
references/learnings.mdto gather accumulated platform knowledge before interacting with the user. - Boundary markers: There are no instructions provided to the agent to treat the content of the learnings file as untrusted data or to ignore any embedded instructions that might be present in that file.
- Capability inventory: The skill facilitates complex configurations of email accounts and AI models, and the agent has the capability to modify local files and interact with user-provided data.
- Sanitization: The skill lacks any mechanism to sanitize or validate the content written to or read from the
learnings.mdfile, which could allow a malicious user or data source to influence the agent's future behavior.
Audit Metadata