sales-multichannel-selling

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a learning pattern via references/learnings.md. 1. Ingestion point: references/learnings.md is read at start. 2. Boundary markers: Absent. 3. Capability inventory: Instructions allow appending new knowledge to references/learnings.md. 4. Sanitization: Absent. This structural pattern creates a surface for indirect prompt injection where untrusted data saved to the learning file could be interpreted as instructions in future sessions.
  • [COMMAND_EXECUTION]: The documentation includes the command npx skills add sales-skills/sales. This command is intended to install related skills from the same author's suite. While it involves shell execution, it is a documented part of the vendor's legitimate integration workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:16 PM
Security Audit — agent-trust-hub — sales-multichannel-selling