lead-research
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze data from untrusted external sources, which creates a potential surface for indirect prompt injection.
- Ingestion points: The workflow involves researching company websites, job postings, GitHub repositories, and news announcements (SKILL.md).
- Boundary markers: There are no instructions to use delimiters or ignore embedded prompts within the external content being researched.
- Capability inventory: The skill relies on the agent's external search and browsing capabilities to collect information.
- Sanitization: There are no specific steps provided to sanitize or filter the data retrieved from external sources before the agent processes it.
Audit Metadata