cold-email-list-quality

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill operates entirely on local CSV and JSONL data using standard Python libraries (csv stdlib) without external network dependencies.- [COMMAND_EXECUTION]: Invokes a local Python script scripts/score_list.py to process list data. This is a standard functional component of the skill's documented purpose.- [DATA_EXPOSURE]: Processes email and prospect data but does not exfiltrate it; results are written to local files (.cleaned.csv and .removed.csv) for user review.- [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted prospect data (names, roles, companies), it treats these as data fields for scoring and does not execute them as instructions or pass them to an LLM for reasoning in a way that suggests a high-risk injection surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 10:27 PM
Security Audit — agent-trust-hub — cold-email-list-quality