gtm-account-research
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from web access and 'supplied packets' in a context that includes internal organization files.\n
- Ingestion points: External web content and user-supplied data packets mentioned in
SKILL.mdandreferences/evidence.md.\n - Boundary markers: The skill defines specific output sections (
Findings,Unverified claims,Hypotheses,Conflicts) to separate inspected facts from unverified external claims.\n - Capability inventory: The agent can read local markdown files from
~/.gtm/and perform web research.\n - Sanitization: Explicitly instructs the agent to detect and withhold 'unsafe' links containing credentials or session identifiers.\n- [DATA_EXFILTRATION]: The skill's workflow involves reading internal data (ICPs, personas, org profiles) from
~/.gtm/and then performing web research. This interaction pattern could be leveraged by an indirect prompt injection to leak internal data to an external server via web requests.
Audit Metadata