closed-lost-revival

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is composed strictly of Markdown documentation and instructions. It does not include any Python scripts, Node.js modules, shell commands, or configuration files that could be used to execute code or manipulate the host system.
  • [INDIRECT_PROMPT_INJECTION]: The instructions describe an agentic workflow that ingests data from external sources, which is a potential surface for indirect prompt injection. * Ingestion points: The agent is directed to read information from CRM records (objections, contact dates), LinkedIn profiles (employment history), and email threads (past conversations) as evidence for drafting. * Boundary markers: The instructions do not specify the use of delimiters or specific guarding instructions when interpolating this data into prompts. * Capability inventory: The skill is limited to drafting text; there are no specified capabilities for file system modification, network communication, or code execution. * Sanitization: The risk is mitigated by a 'Human Approval Contract' which explicitly states that nothing is sent autonomously and every draft must pass through a human review queue.
  • [SAFE]: The implementation of a human review requirement for all agent outputs ensures that any potential malicious content or errors resulting from processed data are intercepted before they can cause harm.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 06:43 AM
Security Audit — agent-trust-hub — closed-lost-revival