lead-finder

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Untrusted Data Ingestion]: The skill reads data from external web sources and user-uploaded files as defined in SKILL.md and reference/sourcing.md. It contains a specific directive to ignore instructions found within this data, which serves as a boundary marker against indirect prompt injection.
  • [Capability Inventory and Risk Management]: The skill has the ability to read financial records and write to CRM systems. These capabilities are managed through mandatory human-in-the-loop approval steps and explicit instructions to report suspicious content to the user without actioning them.
  • [Secure CRM Integration]: The process for writing leads to HubSpot includes a verification step where the agent must state exactly what will be created and wait for an explicit user command to proceed, preventing unauthorized data injection into internal systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:06 PM
Security Audit — agent-trust-hub — lead-finder