win-loss-analysis
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests and processes untrusted external data in the form of deal notes, call summaries, and interview responses, which constitutes an indirect prompt injection vulnerability surface.\n
- Ingestion points: External data enters the agent context via the
Readtool or user input during the data gathering workflow defined inSKILL.md.\n - Boundary markers: The instructions lack explicit delimiters or specific directives to the agent to disregard instructions embedded within the analyzed data.\n
- Capability inventory: The skill is granted
ReadandWritetool access to handle files within the workspace environment.\n - Sanitization: There is no evidence of validation or sanitization of the deal data to prevent the execution of hidden prompts.
Audit Metadata