portfolio-deal-linker
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests unstructured data from multiple external sources which could be used to host malicious instructions designed to manipulate the attribution logic or the content of the generated career portfolio.
- Ingestion points: The skill reads deal notes and activity history from HubSpot, message threads from Gmail, and campaign data from Apollo.
- Boundary markers: There are no specific instructions to wrap external content in delimiters or to use explicit 'ignore' warnings to prevent the agent from obeying instructions embedded within the ingested data.
- Capability inventory: The agent has the ability to write to local files (~/.claude/portfolio/portfolio.jsonl), perform further queries across business platforms (HubSpot, Apollo, Gmail), and generate summarized reports for executive review.
- Sanitization: The instructions do not describe any sanitization, filtering, or validation steps for the unstructured text data before it is processed by the attribution engine.
Audit Metadata