discover-by-domain
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by fetching and processing untrusted content from various web sources during the company enumeration process.\n
- Ingestion points: Web content from industry articles, VC maps, and forum threads (SKILL.md, Step 3).\n
- Boundary markers: Absent; there are no instructions to the agent to disregard instructions within the fetched data.\n
- Capability inventory: File writing, directory creation via Bash, and web access.\n
- Sanitization: No sanitization of external data is specified before it is incorporated into the research notes.\n- [DATA_EXFILTRATION]: The skill accesses a local CRM/outreach log (outreach.md). Although this is used to prevent duplicate outreach, the availability of network tools alongside access to local logs constitutes a data exposure surface.\n- [COMMAND_EXECUTION]: The skill utilizes limited Bash capabilities (mkdir, test) to ensure the directory structure for domain notes is correctly initialized and maintained.
Audit Metadata