skills/affaan-m/ecc/lead-intelligence/Gen Agent Trust Hub

lead-intelligence

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of ingesting and processing untrusted external content.
  • Ingestion points: Data is ingested in enrichment-agent.md and signal-scorer.md from external sources including Exa web search results, X (Twitter) posts, and GitHub profiles.
  • Boundary markers: The instructions do not implement delimiters or 'ignore' instructions to separate external data from the agent's system prompt.
  • Capability inventory: The agents possess high-privilege capabilities including the Bash tool and network access via WebFetch.
  • Sanitization: No explicit sanitization or validation steps are defined for the data retrieved from social media or web searches.
  • [COMMAND_EXECUTION]: The enrichment-agent, mutual-mapper, and signal-scorer agents are configured with the Bash tool. The skill further indicates the use of desktop automation to interact with Apple Mail (Mail.app) for creating drafts, which typically relies on shell-based execution paths.
  • [EXTERNAL_DOWNLOADS]: The skill connects to and downloads data from several external services including the X API, Exa Search API, and various public web domains for lead enrichment and signal scoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:47 PM
Security Audit — agent-trust-hub — lead-intelligence