deal-blocker-maneuvers
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is implemented as a collection of markdown instructions and reference files. It does not contain any executable scripts, binary files, or network-bound commands.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as call recordings, transcripts, and emails stored in the user-configured context layer. This creates a surface for indirect prompt injection; however, the skill possesses no high-risk capabilities like automated file system writes, shell access, or network exfiltration that could be exploited. It explicitly mandates human review for any updates to deal records.
- Ingestion points: Context layer defined by the {{CONTEXT_LAYER}} placeholder in SKILL.md.
- Boundary markers: The skill relies on natural language instructions to separate evidence from analysis but lacks formal delimiters.
- Capability inventory: No subprocess calls, network operations, or automated file writes were detected in the skill content.
- Sanitization: No explicit sanitization or filtering of external content is described.
- [FRONTMATTER_RULE]: The YAML frontmatter contains standard platform metadata and configuration that correctly restricts the skill's scope without introducing new vulnerabilities.
Audit Metadata