lead-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface due to its core functionality of ingesting untrusted data from the web.
- Ingestion points: Data is pulled from external social media profiles (X, LinkedIn) and web search results (Exa) via the
WebSearchandWebFetchtools inenrichment-agent.md,signal-scorer.md, andmutual-mapper.md. - Boundary markers: The instructions do not specify any delimiters or safety warnings to treat lead-derived data as untrusted or to ignore embedded instructions within bios, tweets, or company news.
- Capability inventory: The sub-agents possess high-capability tools including
Bash,Apple Mail(for drafting), andBrowser control(for social media interactions). - Sanitization: There is no mention of sanitizing, filtering, or escaping external content before it is processed by the LLM to generate outreach drafts.
- [COMMAND_EXECUTION]: The
signal-scorer,mutual-mapper, andenrichment-agentsub-agents are explicitly granted access to theBashtool. While intended for data processing and graph analysis, this provides a broad attack surface for arbitrary code execution if the agent is manipulated by malicious content found in a lead's profile. - [CREDENTIALS_UNSAFE]: The skill requires the configuration of multiple sensitive credentials as environment variables, including
X_BEARER_TOKEN,X_ACCESS_TOKEN,X_ACCESS_TOKEN_SECRET,X_CONSUMER_KEY,X_CONSUMER_SECRET, andLINKEDIN_COOKIE. While the instructions follow the safe practice of using environment variables rather than hardcoding, these are high-value secrets that grant the agent significant permissions on the user's social accounts.
Audit Metadata