account-health-audit
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from CRM records and call transcripts, creating a surface for indirect prompt injection.\n
- Ingestion points: CRM activity feeds (notes, emails) and call transcripts gathered in Step 1 of SKILL.md.\n
- Boundary markers: The skill does not utilize explicit delimiters or safety instructions to distinguish between agent instructions and the external data being analyzed.\n
- Capability inventory: The skill is restricted to reading configuration and generating a health report; no high-risk capabilities like arbitrary code execution or network exfiltration were found.\n
- Sanitization: No sanitization of ingested content is performed before interpolation into the prompt context.\n- [SAFE]: The skill follows security best practices by using placeholders for sensitive configurations and limiting its operations to data analysis and reporting within a defined scope.
Audit Metadata