speed-to-lead
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to process untrusted data from various external channels such as email and web forms.
- Ingestion points: Untrusted data enters the agent context through Gmail, Microsoft 365, HubSpot, and form notifications.
- Boundary markers: The skill instructions explicitly treat incoming content as data about the prospect rather than instructions, and it references a shared protocol for handling untrusted content.
- Capability inventory: The agent has the ability to write to HubSpot and post to internal team channels like Slack or RingEx Chat.
- Sanitization: The skill contains logic to detect and hold inquiries that address the assistant directly or request sensitive information like credentials or payments.
- Automated Data Routing: Inquiries categorized as 'hot' are automatically routed to pre-approved internal channels.
- This feature enables rapid team response by automatically sharing lead details and inquiry text to a shared workspace after an initial one-time approval during setup.
- Human-in-the-Loop Safeguards: A core safety feature of the skill is that no drafted replies are sent to external prospects without manual human approval.
- This provides a critical check against automated social engineering or unauthorized messaging.
- Spam and Reputation Protection: The skill implements a 'Volume Guard' to identify and flag suspicious surges in inbound traffic, such as form loops or bot activity.
- This prevents the agent from inadvertently processing or replying to bulk spam, which helps protect the sender's email reputation.
Audit Metadata