deal
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [SAFE]: The skill logic is focused on business sales workflows and does not contain any suspicious code, obfuscated commands, or remote dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted user input.
- Ingestion points:
SKILL.mdaccepts arbitrary user input through the{{args}}placeholder. - Boundary markers: No delimiters or protective instructions are used to separate user data from agent instructions.
- Capability inventory: The skill environment allows access to
Bash,Write,Edit,WebFetch, andGlobtools. - Sanitization: No input validation or sanitization is performed on the arguments passed to the sub-skills.
Audit Metadata