NYC

deal-desk

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWNO_CODE
Full Analysis
  • [NO_CODE] (SAFE): The skill consists exclusively of markdown text (SKILL.md) and metadata. There are no associated scripts (.py, .js, .sh), binaries, or automation configurations.
  • [Indirect Prompt Injection] (LOW): While the skill defines a framework for processing external data such as 'negotiation notes' and 'competitor intel' (SKILL.md), it provides no implementation code to perform these actions. The vulnerability surface exists in the business logic itself rather than the skill's technical content. 1. Ingestion: Deal intake forms, negotiation notes. 2. Boundary markers: Absent. 3. Capability inventory: Syncing to CRM/billing, coordinating approvals. 4. Sanitization: None provided.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 10:41 AM