gtm-account-research

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from web access and 'supplied packets' in a context that includes internal organization files.\n
  • Ingestion points: External web content and user-supplied data packets mentioned in SKILL.md and references/evidence.md.\n
  • Boundary markers: The skill defines specific output sections (Findings, Unverified claims, Hypotheses, Conflicts) to separate inspected facts from unverified external claims.\n
  • Capability inventory: The agent can read local markdown files from ~/.gtm/ and perform web research.\n
  • Sanitization: Explicitly instructs the agent to detect and withhold 'unsafe' links containing credentials or session identifiers.\n- [DATA_EXFILTRATION]: The skill's workflow involves reading internal data (ICPs, personas, org profiles) from ~/.gtm/ and then performing web research. This interaction pattern could be leveraged by an indirect prompt injection to leak internal data to an external server via web requests.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 03:45 PM
Security Audit — agent-trust-hub — gtm-account-research