podcast-personalization-research

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from the web to synthesize outreach openers.
  • Ingestion points: Content extracted from external podcast episode pages and show notes via the WebFetch tool (Step 4).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched web content as untrusted or to ignore instructions contained within that content.
  • Capability inventory: The skill uses mcp__claude_ai_Amplemarket__enrich_person, mcp__claude_ai_Amplemarket__enrich_company, WebSearch, and WebFetch to generate personalization data.
  • Sanitization: No specific sanitization or filtering is applied to the content retrieved from external URLs before it is processed for synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 11:36 PM
Security Audit — agent-trust-hub — podcast-personalization-research