crm-automation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various untrusted external sources, creating a surface for indirect prompt injection.
- Ingestion points: External data enters the system through webhooks (form submissions), CRM queries (HubSpot, Salesforce, Pipedrive), and enrichment APIs (Clearbit, LinkedIn).
- Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within the interpolated data (e.g., Lead Data: {lead_data}).
- Capability inventory: The skill has broad permissions, including writing to multiple CRMs, sending automated emails to leads, and posting messages to Slack channels.
- Sanitization: There is no evidence of data sanitization, validation, or escaping logic applied to external inputs before they are used in AI prompts or outreach templates.
Audit Metadata