lead-intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external data from social media and web searches to score leads and draft outreach. This creates a surface where maliciously crafted external profiles or posts could influence the agent's behavior.
- Ingestion points:
signal-scorer.mdandenrichment-agent.mdfetch content from Exa, X API, GitHub, and general web URLs. - Boundary markers: Absent; the agent instructions do not include specific delimiters or warnings to ignore instructions embedded in the fetched data.
- Capability inventory: The agents have access to
Bash(insignal-scorer.md,enrichment-agent.md, andmutual-mapper.md),WebSearch,WebFetch, and integrations forApple Mailand browser automation mentioned inSKILL.md. - Sanitization: No explicit sanitization, validation, or escaping of the external content is required in the agent prompts.
Audit Metadata