skills/sales-skills/sales/sales-sally/Gen Agent Trust Hub

sales-sally

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of meeting transcripts and summaries, which could theoretically contain malicious instructions. However, this is inherent to its primary purpose as a meeting assistant.\n
  • Ingestion points: Meeting transcripts, summaries, and metadata retrieved via Sally AI MCP tools as described in references/platform-guide.md and references/sally-api-reference.md.\n
  • Boundary markers: The skill does not currently define specific delimiters to separate meeting data from instructions.\n
  • Capability inventory: Includes network operations to the Sally AI API and file writing to references/learnings.md for persistent state.\n
  • Sanitization: No explicit sanitization of transcript content is performed before processing or storage in local learning logs.\n- [EXTERNAL_DOWNLOADS]: The documentation references the installation of related sales skills and a remote MCP proxy utility.\n
  • Evidence: Provides instructions for using npx skills add to install other skills from the sales-skills repository and npx mcp-remote for legacy client support.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:32 AM
Security Audit — agent-trust-hub — sales-sally