outreach-composer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection Surface: The skill ingests data from external sources such as prospect websites via WebFetch and enrichment tools like Apollo or Clay to ground its outreach messages. This data is interpolated into the message generation process, which could potentially allow for indirect prompt injection if those sources contain malicious or deceptive instructions intended to influence the agent's output.
  • Ingestion points: External websites (WebFetch), CRM notes and emails (HubSpot), and enrichment service data (Apollo, Clay).
  • Boundary markers: The instructions do not define explicit delimiters or "ignore instructions" warnings for the external data being processed.
  • Capability inventory: The skill can send emails via Gmail, Microsoft 365, or Mailchimp connectors, write to the voice-profile.md file, and log data to HubSpot.
  • Sanitization: There is no mention of specific sanitization, filtering, or validation of the content ingested from external websites or tools before it is processed by the model.
  • Processing of Sent Mail for Voice Profiling: The skill is designed to pull 15 to 30 of the user's sent messages from Gmail or Microsoft 365 to build a voice profile. While this is a core functionality intended to improve voice fidelity, it involves the automated reading and analysis of potentially sensitive or confidential personal and business communications.
  • High-Consequence Action Capabilities: The skill performs actions with real-world impact, including sending emails under the user's name and modifying CRM records. The skill includes procedural safeguards, such as requiring explicit approval gates before any batch is sent, which helps mitigate the risk of unintended actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:05 PM
Security Audit — agent-trust-hub — outreach-composer