sales-call-prep
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to access and aggregate highly sensitive data from multiple sources to create its report. This includes reading deal values, contact interaction history, and private notes from CRM platforms (Salesforce, HubSpot, Attio) and outreach tools (SmartLead, Instantly). While this is the intended functionality, it establishes a high-value data access pattern.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it fetches and processes untrusted content from external web sources.
- Ingestion points: Step 2 (Company Deep Dive) and Step 3 (Person Deep Dive) utilize web search to ingest data from company websites, LinkedIn profiles, social media posts, and news articles.
- Boundary markers: The instructions do not specify any delimiters or boundary markers to isolate external content, nor do they instruct the agent to ignore potentially malicious instructions embedded in that content.
- Capability inventory: The agent possesses capabilities for
web-search,contact-finding, anddata-analysis, along with the ability to read from local file paths and third-party CRM integrations. - Sanitization: There is no mention of sanitizing or validating external data before it is mapped to the internal product context and used to generate the final call strategy.
Audit Metadata