lead-research-assistant
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze the user's local codebase to understand the product and to perform web searches for lead identification. This creates a vulnerability surface where malicious instructions embedded in project files or on third-party websites could influence the agent's actions.
- Ingestion points: The skill processes local files via the instruction to "analyze the codebase" and external web data through the instruction to "Search for companies matching the criteria".
- Boundary markers: The instructions lack explicit directives for the agent to ignore or delimit instructions found within the processed data.
- Capability inventory: The skill requires the ability to read local files and perform web searches to fulfill its primary purpose.
- Sanitization: There is no mechanism described to sanitize or filter potential instructions found in the ingested data.
Audit Metadata