discover-by-domain

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by fetching and processing untrusted content from various web sources during the company enumeration process.\n
  • Ingestion points: Web content from industry articles, VC maps, and forum threads (SKILL.md, Step 3).\n
  • Boundary markers: Absent; there are no instructions to the agent to disregard instructions within the fetched data.\n
  • Capability inventory: File writing, directory creation via Bash, and web access.\n
  • Sanitization: No sanitization of external data is specified before it is incorporated into the research notes.\n- [DATA_EXFILTRATION]: The skill accesses a local CRM/outreach log (outreach.md). Although this is used to prevent duplicate outreach, the availability of network tools alongside access to local logs constitutes a data exposure surface.\n- [COMMAND_EXECUTION]: The skill utilizes limited Bash capabilities (mkdir, test) to ensure the directory structure for domain notes is correctly initialized and maintained.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 05:16 AM
Security Audit — agent-trust-hub — discover-by-domain