brida-reflex-sales-lead-fit
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is instructed to fetch live availability and configuration data from the vendor's infrastructure using files such as
/reflex/llms.txt,/reflex/agent.md, and/reflex/agent.json. - [INDIRECT_PROMPT_INJECTION]: The skill processes external lead data (facts) which is potentially untrusted content.
- Ingestion points: Lead facts and firmographic data are ingested from the project environment, conversation, or connected tools as defined in the
SKILL.mdandreferences/playbook.mdfiles. - Boundary markers: The skill uses a structured JSON contract (
references/custom-reflex.json) to define the exact versioned public contract and expected output branches. - Capability inventory: The skill instructions explicitly state that the Reflex result never grants permission for protected actions such as payments, deploys, external messages, or account changes.
- Sanitization: The instructions require that parsing, policy, and authorization remain in deterministic host code, and the data class is restricted to non-sensitive information.
Audit Metadata