podcast-personalization-research
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from the web to synthesize outreach openers.
- Ingestion points: Content extracted from external podcast episode pages and show notes via the
WebFetchtool (Step 4). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched web content as untrusted or to ignore instructions contained within that content.
- Capability inventory: The skill uses
mcp__claude_ai_Amplemarket__enrich_person,mcp__claude_ai_Amplemarket__enrich_company,WebSearch, andWebFetchto generate personalization data. - Sanitization: No specific sanitization or filtering is applied to the content retrieved from external URLs before it is processed for synthesis.
Audit Metadata