sales-observe-ai
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides enterprise contact center intelligence guidance and platform information. No malicious behaviors were detected.
- [PROMPT_INJECTION]: The skill uses a learning file (
references/learnings.md) to persist knowledge across sessions. This creates a surface for indirect prompt injection where data from one session could influence future sessions. - Ingestion points:
references/learnings.mdis read at the start of each invocation. - Boundary markers: No explicit delimiters or warnings are used for the content in the learning file.
- Capability inventory: The skill instructs the agent to route questions to other sales-related skills and provides reference information.
- Sanitization: No sanitization is performed on the data appended to the learning file.
- [EXTERNAL_DOWNLOADS]: The skill references legitimate external resources including official documentation (
api-docs.observe.ai) and third-party research sites (semarize.com,apitracker.io) for API details. It also mentions an installation command for a related skill from the same vendor (sales-skills/sales). These are documented for informational purposes and do not involve unauthorized remote code execution.
Audit Metadata