personalize-email
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is entirely composed of markdown instructions and lacks any executable scripts, binary files, or automated network execution patterns. Technical analysis confirms the absence of direct prompt injection, obfuscation techniques, or persistence mechanisms.
- [PROMPT_INJECTION]: The skill outlines a workflow that ingests untrusted external data, such as LinkedIn posts and website content, representing an indirect prompt injection surface. 1. Ingestion points: External data is pulled from social profiles and company websites. 2. Boundary markers: The instructions do not define specific delimiters or directives to ignore instructions embedded in the collected data. 3. Capability inventory: The skill gathers and ranks data for use by a downstream drafting model. 4. Sanitization: No validation or sanitization of the external content is described.
Audit Metadata