skills/ericrisco/rsc-harness/lead-gen/Gen Agent Trust Hub

lead-gen

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and qualify prospect data from external B2B databases and APIs (Apollo, ZoomInfo, Clay), which represents a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to ingest data from Apollo Search and Enrichment endpoints, as detailed in SKILL.md and references/data-sources.md.
  • Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags) to isolate external prospect data when processed by the agent, though it emphasizes structured CSV output.
  • Capability inventory: The skill includes a local bash script (scripts/verify.sh) for CSV validation. Primary capabilities such as email outreach and CRM management are delegated to separate, specialized skills.
  • Sanitization: The skill includes mandatory email verification passes to check for validity and deliverability before data is used in downstream tasks.
  • [SAFE]: The external service references (Apollo, ZoomInfo) are established B2B platforms, and documentation links target legitimate industry resources. The provided utility script (scripts/verify.sh) is a read-only linter that does not perform network operations or require elevated privileges.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — lead-gen