event-account-plan
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructs the agent to generate and execute local scripts to process large datasets that exceed the context window. Evidence: references/signal-sourcing.md states: "write a small script that parses every saved result file and keep the raw payloads out of the conversation entirely."
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external attendee lists which could be used as a vector for malicious instructions to influence the agent's logic or scoring. Evidence Chain:
- Ingestion points: SKILL.md (attendee list provided as an export, sheet, or text paste).
- Boundary markers: No delimiters or "ignore embedded instructions" warnings are specified for the input data.
- Capability inventory: The skill uses network-enabled connectors for company data and contact searches, and writes output to shared war-room pages and files.
- Sanitization: The instructions do not specify sanitization or validation for the incoming attendee data.
Audit Metadata