sales-xperiencify
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by processing external data from the Xperiencify platform.
- Ingestion points: The skill ingests student profile information, including names, emails, tags, and custom fields, from the REST API endpoints and webhook data exports described in
references/xperiencify-api-reference.md. - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from interpreting instructions that might be embedded within these data fields.
- Capability inventory: The agent uses this untrusted data to generate contextual information for the user and to guide routing to external systems like CRMs or email service providers, creating a path for malicious data to influence agent behavior.
- Sanitization: The skill does not implement or describe any sanitization or filtering of the student data before it is incorporated into the agent's reasoning process.
Audit Metadata