sales-viralnation
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a self-improvement mechanism that appends new findings to 'references/learnings.md', which is read at the start of every session to provide context. This creates a surface for indirect prompt injection. \n * Ingestion points: User input provided in Step 1 of SKILL.md. \n * Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands when writing or reading from the learnings file. \n * Capability inventory: The agent has instructions to append content to 'references/learnings.md'. \n * Sanitization: Absent; the skill does not specify any validation or filtering of content before it is persisted to the learnings file. \n- [COMMAND_EXECUTION]: The documentation includes a command 'npx skills add sales-skills/sales --skills sales-do' used to install a related utility from the same vendor ('sales-skills').
Audit Metadata