lead-routing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted lead data during the AI-powered lead scoring phase, which presents an attack surface for indirect prompt injection.
- Ingestion points: Lead data is dynamically loaded via the
{lead_data}variable withinSKILL.mdunder theai_scoringprompt configuration. - Boundary markers: Absent. The template places the variable directly beneath text headers without XML/Markdown tags or explicit structural delimiters to separate untrusted inputs from developer instructions.
- Capability inventory: The skill interacts with the
crm-mcpserver tools (hubspot_assign_owner,salesforce_route, andenrichment_api) to assign ownership, route leads, and perform notifications via Slack. - Sanitization: Absent. No preprocessing or input filtering is specified for the lead data fields prior to prompt interpolation.
Audit Metadata