icp-refiner
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses official Amplemarket MCP tools and standard web search capabilities to perform its stated functions. Its behavior is consistent with the author's provided documentation.
- [SAFE]: No obfuscation, hardcoded credentials, or suspicious exfiltration patterns were detected. Data handling is limited to the scope of ICP refinement.
- [PROMPT_INJECTION]: The skill ingests untrusted data from web search results and company enrichment API calls, creating a surface for indirect prompt injection. This is a low-risk concern inherent to the skill's research-based functionality.
- Ingestion points:
WebSearchresults andmcp__claude_ai_Amplemarket__*API tool outputs (enrichment, search results). - Boundary markers: Not explicitly implemented in the prompt instructions to separate untrusted tool output from internal logic.
- Capability inventory: Tool access includes web searching, firmographic enrichment, and lead list management within the Amplemarket platform.
- Sanitization: The agent is instructed to analyze and extract patterns from the ingested content; no explicit sanitization for subverting instructions is noted.
Audit Metadata