persona-sales-ops

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill orchestrates workflows that process external, untrusted data, which presents an inherent surface for indirect prompt injection attacks.\n
  • Ingestion points: The skill instructs the agent to process data from Gmail and Sheets via referenced tools.\n
  • Boundary markers: No explicit instructions are present to ensure the agent ignores or sanitizes instructions embedded in external content.\n
  • Capability inventory: The persona uses tools capable of reading, writing, and uploading files to Gmail, Calendar, Sheets, and Drive.\n
  • Sanitization: No sanitization mechanisms are described for data retrieved from external communication or documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:16 PM
Security Audit — agent-trust-hub — persona-sales-ops