know-before-you-go-perla-lobera
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and synthesize data from several untrusted or semi-trusted sources, creating a surface where malicious instructions could influence the agent's behavior or output.
- Ingestion points: The skill reads Granola transcripts, Outreach email history, and real-time Web Search results (including blogs, job postings, and reviews) in Step 2.
- Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' tags when processing content from these external sources.
- Capability inventory: The agent performs complex synthesis and generates an HTML document based on the gathered data.
- Sanitization: Absent. There is no requirement for the agent to sanitize, escape, or validate the content retrieved from external URLs or search results before including it in the synthesized brief.
- [DATA_EXFILTRATION]: The skill accesses and consolidates highly sensitive business intelligence across multiple silos (Salesforce, Outreach, Amplitude, and Granola). While this is the intended purpose of the skill, the aggregation of customer transcripts, deal stages, and private email threads into a single portable HTML document increases the potential impact of data exposure if the brief is mishandled.
Audit Metadata