route-lead

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to process content from potentially untrusted external sources like CRM records, emails, chat transcripts, and manually pasted lead data.
  • Ingestion Points: Untrusted data enters the agent context through CRM lookups, email/chat integration tools, and user-provided lead content in SKILL.md.
  • Boundary Markers: The skill includes robust internal instructions for the agent to treat these sources strictly as data and explicitly ignore any embedded instructions.
  • Capability Inventory: The skill is capable of performing CRM record updates (ownership changes), posting handoff notes to chat, and drafting emails.
  • Sanitization: The instructions include a mandatory human-in-the-loop review process for any action identified as 'content-originated,' ensuring that a human router verifies targets and message content before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:05 PM
Security Audit — agent-trust-hub — route-lead