investor-outreach
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes web search capabilities to research external data from sources like LinkedIn, Twitter, and Crunchbase (Phase 1). This creates a surface for indirect prompt injection, where an adversary could place malicious instructions on a web page to manipulate the agent's research output or email drafting.
- Ingestion points: External web search results (SKILL.md).
- Boundary markers: Absent. The instructions do not define delimiters for searched content or instruct the agent to ignore embedded commands in search results.
- Capability inventory: The agent generates personalized email drafts and builds a CRM pipeline based on external research.
- Sanitization: Absent. There is no evidence of logic to validate or escape data retrieved from the web before it is incorporated into the outreach templates.
- [NO_CODE]: The skill consists entirely of markdown instructions and templates. No executable scripts, binaries, or automated tool configurations were detected.
Audit Metadata