alliance-gtm
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill is composed of Markdown instructions and YAML templates for managing alliance go-to-market motions. It contains no executable scripts, shell commands, or binary files.
- [PROMPT_INJECTION]: The skill identifies ingestion points for external data such as partner agreements and target account lists, which creates a surface for indirect prompt injection. However, the risk is mitigated as the skill lacks capabilities like network access or file-system modification that could be exploited by such an injection.
- Ingestion points: Partner agreements, profiles, and account lists defined in the Inputs and Phase 1 sections.
- Boundary markers: None explicitly defined in the templates.
- Capability inventory: No code execution, network operations, or file-write capabilities identified in the skill body.
- Sanitization: No input validation or sanitization logic is present.
Audit Metadata