gtm-lead-scoring
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted lead facts and labels, which represents an indirect prompt injection surface.
- Ingestion points: User-supplied lead facts and persona labels processed in
SKILL.md. - Boundary markers: None defined for the interpolation of untrusted lead facts.
- Capability inventory: The skill is restricted to reading persona files from the
~/.gtm/directory and is explicitly barred from network access or system changes. - Sanitization: Instructions in
references/context.mddirect the agent to filter out credentials, tokens, and session identifiers from input data. - [NO_CODE]: The skill consists entirely of markdown instructions and references, containing no executable scripts or binaries.
Audit Metadata