draft-outreach

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest data from external, potentially untrusted sources (web search, social profiles, enrichment APIs) and incorporate it into drafted messages.
  • Ingestion points: Data enters the context during Step 2 ('Research First') where the skill instructions specify fetching company and personal details from the web, enrichment services, and CRM databases.
  • Capability inventory: The skill has the capability to output text directly to the user and can also create email drafts in a user's inbox if the email connector is active.
  • Boundary markers & Sanitization: The instructions do not define explicit boundary markers or sanitization logic for the external data retrieved during research. This creates a scenario where crafted content on a prospect's public profile or website could influence the agent's behavior or the content of the drafted outreach.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 PM