lead-routing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted lead data during the AI-powered lead scoring phase, which presents an attack surface for indirect prompt injection.
  • Ingestion points: Lead data is dynamically loaded via the {lead_data} variable within SKILL.md under the ai_scoring prompt configuration.
  • Boundary markers: Absent. The template places the variable directly beneath text headers without XML/Markdown tags or explicit structural delimiters to separate untrusted inputs from developer instructions.
  • Capability inventory: The skill interacts with the crm-mcp server tools (hubspot_assign_owner, salesforce_route, and enrichment_api) to assign ownership, route leads, and perform notifications via Slack.
  • Sanitization: Absent. No preprocessing or input filtering is specified for the lead data fields prior to prompt interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:53 PM
Security Audit — agent-trust-hub — lead-routing