route-lead
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to process content from potentially untrusted external sources like CRM records, emails, chat transcripts, and manually pasted lead data.
- Ingestion Points: Untrusted data enters the agent context through CRM lookups, email/chat integration tools, and user-provided lead content in
SKILL.md. - Boundary Markers: The skill includes robust internal instructions for the agent to treat these sources strictly as data and explicitly ignore any embedded instructions.
- Capability Inventory: The skill is capable of performing CRM record updates (ownership changes), posting handoff notes to chat, and drafting emails.
- Sanitization: The instructions include a mandatory human-in-the-loop review process for any action identified as 'content-originated,' ensuring that a human router verifies targets and message content before execution.
Audit Metadata