daily-web-signal-prospector

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its stated purpose of sales prospecting. It uses official tools from the author's service (Amplemarket) to enrich company data and find people, representing legitimate vendor functionality.
  • [PROMPT_INJECTION]: The skill retrieves and processes untrusted content from the web via WebSearch and WebFetch. This creates a surface for indirect prompt injection, where an attacker could embed malicious instructions in search results or web pages to influence the agent's data extraction or lead generation logic.
  • Ingestion points: Data extracted from external URLs during the signal research phase.
  • Boundary markers: None mentioned for processed web content.
  • Capability inventory: Amplemarket enrichment, people search, and lead list creation tools.
  • Sanitization: No specific sanitization or validation of the fetched web text is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 11:36 PM
Security Audit — agent-trust-hub — daily-web-signal-prospector