prospect-icp-search

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions do not contain any attempts to override system behavior, bypass safety guidelines, or extract system prompts. The instructions are focused entirely on the intended prospecting functionality.
  • [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data access or exfiltration. The skill interacts with the Amplemarket API using standard tool calls and does not attempt to access sensitive files (e.g., .ssh, .aws) or send data to untrusted external domains.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code downloads or execution. It relies on pre-defined MCP tools for its operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input to define search criteria.
  • Ingestion points: User-provided descriptions of ideal prospects in natural language.
  • Boundary markers: None explicitly defined for user input within the instructions.
  • Capability inventory: The skill uses tools to resolve industries/job functions and execute searches (mcp__claude_ai_Amplemarket__search_people).
  • Sanitization: The skill instructs the agent to map user input into specific structured enums (e.g., seniority levels, company sizes) and resolve values via API before searching, which mitigates the risk of direct instruction injection through the search parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 11:36 PM
Security Audit — agent-trust-hub — prospect-icp-search