sales-newmail
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill implements a persistent memory mechanism via
references/learnings.md, which is used to store and retrieve user-influenced tips and gotchas.\n - Ingestion points:
references/learnings.mdis read during Step 1 of the skill workflow inSKILL.md.\n - Boundary markers: The skill lacks explicit delimiters or instructions to the agent to disregard instructions potentially embedded within the 'learnings' file.\n
- Capability inventory: The skill does not contain standalone scripts or direct command execution (subprocesses, eval, etc.), classifying it primarily as a set of instructions (
NO_CODE).\n - Sanitization: There is no logic to sanitize or validate the content being written to or read from the learning store.\n- [NO_CODE]: The skill consists entirely of Markdown instructions and reference documents. No executable scripts (Python, JavaScript, shell) are included in the package.
Audit Metadata