sales-laserfocus
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to persist new information into references/learnings.md, which creates an attack surface for indirect prompt injection where malicious data from a user could be stored and influence future interactions. Ingestion points: User input and context from Laserfocus platform references. Boundary markers: Absent. Capability inventory: Appending content to a local markdown file. Sanitization: None.
- [COMMAND_EXECUTION]: The skill recommends installing a related tool using the command npx skills add sales-skills/sales --skill sales-do. This command downloads and executes code from a remote registry. This is documented as a standard procedure for the vendor's ecosystem.
Audit Metadata