sales-laserfocus

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to persist new information into references/learnings.md, which creates an attack surface for indirect prompt injection where malicious data from a user could be stored and influence future interactions. Ingestion points: User input and context from Laserfocus platform references. Boundary markers: Absent. Capability inventory: Appending content to a local markdown file. Sanitization: None.
  • [COMMAND_EXECUTION]: The skill recommends installing a related tool using the command npx skills add sales-skills/sales --skill sales-do. This command downloads and executes code from a remote registry. This is documented as a standard procedure for the vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:37 AM
Security Audit — agent-trust-hub — sales-laserfocus