outreach-clarify

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, specifically using the paperclip-wiki-fetch tool to retrieve information from wiki pages and reading lead data from the Twenty CRM. This creates a potential surface for indirect prompt injection if those external sources contain malicious instructions intended to influence the agent's configuration recommendations.
  • Ingestion points: paperclip-wiki-fetch (retrieving documentation), Paperclip Run Records, and Twenty CRM segment data.
  • Boundary markers: The skill does not explicitly define delimiters for external content in SKILL.md.
  • Capability inventory: The skill is strictly non-mutating; it only performs read operations and produces a textual 'Outreach Run Spec' for operator review.
  • Sanitization: No explicit sanitization or filtering of fetched content is described.
  • [DATA_EXPOSURE]: The skill is designed to access sensitive organizational data, including campaign strategies in Paperclip and lead/account data in the Twenty CRM. This access is central to the skill's primary purpose of clarifying outreach runs and is performed within the documented 'operations plane' of the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:26 PM
Security Audit — agent-trust-hub — outreach-clarify