closed-won-replication-play

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection. 1. Ingestion points: SKILL.md (Step 1 — extraction of use cases and pain points from CRM deal notes and contact activity). 2. Boundary markers: Absent; there are no specific instructions to treat extracted notes as untrusted data or use delimiters. 3. Capability inventory: The agent has access to external company and employee search tools, CRM write access to create companies and contacts (Step 5), and notification capabilities via Slack or Email (Step 6). 4. Sanitization: Absent; the skill does not specify any filtering or validation for the extracted deal notes. This risk is primarily mitigated by the mandatory human review step before any outreach is dispatched.
  • [NO_CODE]: The skill is comprised entirely of instructional markdown and does not include any executable scripts, binaries, or software package manifests, which reduces the surface area for traditional code-based exploits.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 04:39 PM
Security Audit — agent-trust-hub — closed-won-replication-play