sales-openhunts
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a self-improvement mechanism that appends information to references/learnings.md based on interactions. This establishes a surface for indirect prompt injection. 1. Ingestion points: Data is ingested through user queries and product descriptions provided during the session. 2. Boundary markers: There are no explicit markers or instructions defined to prevent the agent from executing instructions potentially embedded in the learned content. 3. Capability inventory: The skill possesses the capability to read/write local files and invoke other skills within the author's ecosystem. 4. Sanitization: The instructions do not specify any validation or filtering of content before it is recorded in the persistent learning file.
- [COMMAND_EXECUTION]: The documentation includes an installation command 'npx skills add sales-skills/sales' to add related skills. This is a standard procedure for expanding capabilities using tools provided by the skill's author.
Audit Metadata