lead-finder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Untrusted Data Ingestion]: The skill reads data from external web sources and user-uploaded files as defined in SKILL.md and reference/sourcing.md. It contains a specific directive to ignore instructions found within this data, which serves as a boundary marker against indirect prompt injection.
- [Capability Inventory and Risk Management]: The skill has the ability to read financial records and write to CRM systems. These capabilities are managed through mandatory human-in-the-loop approval steps and explicit instructions to report suspicious content to the user without actioning them.
- [Secure CRM Integration]: The process for writing leads to HubSpot includes a verification step where the agent must state exactly what will be created and wait for an explicit user command to proceed, preventing unauthorized data injection into internal systems.
Audit Metadata