a1-business-message
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external materials such as notes, correspondence, and project documents, which creates a potential surface for indirect prompt injection. * Ingestion points: The skill accepts inputs through the 'Entry Contract' defined in SKILL.md and reads local configuration files like .agents/marketing-context.md. * Boundary markers: The skill employs a 'Message Map' and a 'Diagnostic Boundary' (references/source-policy.md) to isolate facts and prevent the model from adopting unintended instructions or filling gaps with fabricated content. * Capability inventory: The skill's operations are limited to text manipulation and generation. There are no functions for file modification, arbitrary command execution, or network communication. * Sanitization: A mandatory checklist in references/final-qa.md requires verifying that every substantive statement traces to authorized source material and checking that no unsupported completion details are present.
- [SAFE]: The skill instructions and associated reference files do not contain obfuscated code, unauthorized data access, or privilege escalation patterns. The inclusion of a Telegram support link is a transparent feedback mechanism consistent with the skill's authorship.
Audit Metadata