lead-intelligence

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface due to its core functionality of ingesting untrusted data from the web.
  • Ingestion points: Data is pulled from external social media profiles (X, LinkedIn) and web search results (Exa) via the WebSearch and WebFetch tools in enrichment-agent.md, signal-scorer.md, and mutual-mapper.md.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to treat lead-derived data as untrusted or to ignore embedded instructions within bios, tweets, or company news.
  • Capability inventory: The sub-agents possess high-capability tools including Bash, Apple Mail (for drafting), and Browser control (for social media interactions).
  • Sanitization: There is no mention of sanitizing, filtering, or escaping external content before it is processed by the LLM to generate outreach drafts.
  • [COMMAND_EXECUTION]: The signal-scorer, mutual-mapper, and enrichment-agent sub-agents are explicitly granted access to the Bash tool. While intended for data processing and graph analysis, this provides a broad attack surface for arbitrary code execution if the agent is manipulated by malicious content found in a lead's profile.
  • [CREDENTIALS_UNSAFE]: The skill requires the configuration of multiple sensitive credentials as environment variables, including X_BEARER_TOKEN, X_ACCESS_TOKEN, X_ACCESS_TOKEN_SECRET, X_CONSUMER_KEY, X_CONSUMER_SECRET, and LINKEDIN_COOKIE. While the instructions follow the safe practice of using environment variables rather than hardcoding, these are high-value secrets that grant the agent significant permissions on the user's social accounts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — lead-intelligence