lead-research-assistant

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing untrusted data from the web and the user's local file system.
  • Ingestion points: In SKILL.md (Instructions 1 and 3), the agent is directed to analyze the local product codebase and search for external information such as company news, job postings, and website content.
  • Boundary markers: There are no boundary markers or instructions to ignore potential commands embedded in the external or local data being processed.
  • Capability inventory: The skill utilizes file-reading capabilities for codebase analysis and web-search capabilities for lead enrichment.
  • Sanitization: No sanitization, escaping, or validation steps are defined for the information retrieved from external sources before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 01:00 AM
Security Audit — agent-trust-hub — lead-research-assistant