event-account-plan

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to generate and execute local scripts to process large datasets that exceed the context window. Evidence: references/signal-sourcing.md states: "write a small script that parses every saved result file and keep the raw payloads out of the conversation entirely."
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external attendee lists which could be used as a vector for malicious instructions to influence the agent's logic or scoring. Evidence Chain:
  • Ingestion points: SKILL.md (attendee list provided as an export, sheet, or text paste).
  • Boundary markers: No delimiters or "ignore embedded instructions" warnings are specified for the input data.
  • Capability inventory: The skill uses network-enabled connectors for company data and contact searches, and writes output to shared war-room pages and files.
  • Sanitization: The instructions do not specify sanitization or validation for the incoming attendee data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:49 PM
Security Audit — agent-trust-hub — event-account-plan