revops
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that automatically ingests external configuration data, creating a surface for instruction override.\n
- Ingestion points:
SKILL.mddirects the agent to read.agents/product-marketing-context.mdor.claude/product-marketing-context.mdto gather initial task context.\n - Boundary markers: Absent. The instructions do not specify any delimiters or safety prompts to isolate the ingested context from the agent's core instructions.\n
- Capability inventory: The skill provides detailed playbooks for automating CRM operations in HubSpot and Salesforce and connecting workflows via Zapier. These capabilities could be misdirected by a poisoned context file.\n
- Sanitization: Absent. The skill provides no guidance on validating or escaping the content of the markdown files before ingestion.
Audit Metadata