sales-qualified
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues or malicious patterns were detected during the analysis of the skill instructions and reference documents.- [PROMPT_INJECTION]: The skill contains standard instructional logic for context gathering and platform guidance. It does not contain any attempts to bypass safety filters, extract system prompts, or override agent behavior.- [DATA_EXFILTRATION]: While the skill discusses Salesforce integrations and API configurations, it does not include commands to access sensitive local files (like .ssh or .env) or exfiltrate data to external domains.- [EXTERNAL_DOWNLOADS]: The skill includes an example command for adding related skills (
npx skills add sales-skills/sales). These resources belong to the same author ('sales-skills') and represent expected platform functionality.- [INDIRECT_PROMPT_INJECTION]: The skill implements a self-improvement loop by reading from and appending toreferences/learnings.md. This allows the agent to build a persistent knowledge base from user interactions. - Ingestion points:
references/learnings.mdand user prompts. - Boundary markers: Markdown headers and date stamps are used to structure the learning file.
- Capability inventory: No dangerous capabilities (subprocess execution, network operations, or arbitrary file writes) were found in the skill's logic.
- Sanitization: Not explicitly implemented, but the current risk is low given the lack of exploitable tools.
Audit Metadata