investor-outreach

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes web search capabilities to research external data from sources like LinkedIn, Twitter, and Crunchbase (Phase 1). This creates a surface for indirect prompt injection, where an adversary could place malicious instructions on a web page to manipulate the agent's research output or email drafting.
  • Ingestion points: External web search results (SKILL.md).
  • Boundary markers: Absent. The instructions do not define delimiters for searched content or instruct the agent to ignore embedded commands in search results.
  • Capability inventory: The agent generates personalized email drafts and builds a CRM pipeline based on external research.
  • Sanitization: Absent. There is no evidence of logic to validate or escape data retrieved from the web before it is incorporated into the outreach templates.
  • [NO_CODE]: The skill consists entirely of markdown instructions and templates. No executable scripts, binaries, or automated tool configurations were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 10:41 PM
Security Audit — agent-trust-hub — investor-outreach