draft-outreach
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to ingest data from external, potentially untrusted sources (web search, social profiles, enrichment APIs) and incorporate it into drafted messages.
- Ingestion points: Data enters the context during Step 2 ('Research First') where the skill instructions specify fetching company and personal details from the web, enrichment services, and CRM databases.
- Capability inventory: The skill has the capability to output text directly to the user and can also create email drafts in a user's inbox if the email connector is active.
- Boundary markers & Sanitization: The instructions do not define explicit boundary markers or sanitization logic for the external data retrieved during research. This creates a scenario where crafted content on a prospect's public profile or website could influence the agent's behavior or the content of the drafted outreach.
Audit Metadata