sales-motion

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted user input and uses it to update persistent local learning files.
  • Ingestion points: User-provided descriptions and queries about Motion challenges are ingested through the skill's primary execution flow.
  • Boundary markers: Absent. There are no explicit delimiters or instructions provided to the agent to treat the user's input as data rather than instructions.
  • Capability inventory: The skill explicitly instructs the agent to append new information, gotchas, or workarounds discovered during the conversation to references/learnings.md (SKILL.md, Step 4).
  • Sanitization: Absent. The skill does not instruct the agent to validate, escape, or filter the content before writing it to the filesystem, allowing potentially malicious instructions to be stored and executed in future sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:16 PM
Security Audit — agent-trust-hub — sales-motion