account-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructs the agent to generate and execute plain JavaScript snippets on a remote MCP server (https://install.crustdata.com/mcp) to perform data analysis and tool orchestration. Additionally, it directs the agent to generate local Python scripts to build organizational charts.
- [COMMAND_EXECUTION]: The agent is instructed to execute local shell commands, specifically using headless Chrome (e.g.,
google-chrome --headless), to take screenshots of generated HTML files for visual review before presentation to the user. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it processes untrusted data from the web while maintaining access to sensitive internal systems and execution tools.
- Ingestion points: External web search results, enriched content from third-party sites like theorg.com (via
web_enrich_live), social media posts, and internal communications from CRM, Email, and Team Chat systems. - Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore embedded instructions within retrieved data.
- Capability inventory: Remote JavaScript execution on the vendor's MCP server, local Python script generation, and local shell command execution for browser automation.
- Sanitization: Absent; there is no requirement for the agent to sanitize or escape ingested content before using it to synthesize plans or execute logic.
- [DATA_EXFILTRATION]: The skill is designed to read sensitive organizational data from connected connectors (CRM, Call Recorders, Team Chat, Email). While intended for account planning, this data is summarized and processed through the vendor's infrastructure via the Crustdata MCP server.
Audit Metadata