lead-research-assistant

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from multiple external sources, creating a surface for indirect prompt injection attacks where malicious instructions could influence agent behavior.
  • Ingestion points: The instructions direct the agent to analyze the local codebase where the skill is executed, as well as external content from the web including company websites, job postings, news, and public GitHub repositories during the lead research phase (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters provided to help the agent distinguish between the user's research goals and potentially malicious instructions embedded in the external content it analyzes.
  • Capability inventory: The skill utilizes the agent's capabilities to read local files (for codebase analysis) and perform network-based research to identify leads.
  • Sanitization: The instructions do not define any specific sanitization, filtering, or validation steps for the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM