persona-sales-ops
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill orchestrates workflows that process external, untrusted data, which presents an inherent surface for indirect prompt injection attacks.\n
- Ingestion points: The skill instructs the agent to process data from Gmail and Sheets via referenced tools.\n
- Boundary markers: No explicit instructions are present to ensure the agent ignores or sanitizes instructions embedded in external content.\n
- Capability inventory: The persona uses tools capable of reading, writing, and uploading files to Gmail, Calendar, Sheets, and Drive.\n
- Sanitization: No sanitization mechanisms are described for data retrieved from external communication or documents.
Audit Metadata