airtable-automation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes automation workflows that ingest untrusted data from external sources, creating a potential attack surface for indirect prompt injection.
- Ingestion points: Data enters the workflow via typeform_submission, airtable_query, and Clearbit enrichment lookups in SKILL.md.
- Boundary markers: The provided templates do not include explicit delimiters or instructions for the agent to ignore embedded commands in the ingested data.
- Capability inventory: The skill utilizes capabilities for database modification (airtable_create_record, airtable_update_record) and external notifications via Slack and email.
- Sanitization: The workflow templates do not demonstrate data sanitization or validation of the ingested external content before processing.
Audit Metadata