list-building

Fail

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE]: The skill provides a structured framework for B2B list building and orchestrates several specialized sub-skills for tasks such as ICP definition and data validation. All instructions and code are transparent and align with the stated purpose of sales automation.
  • [EXTERNAL_DOWNLOADS]: The skill references various external websites and tools for lead sourcing (e.g., Apollo, LinkedIn Sales Navigator, Clay). While one referenced domain (saasmag.com) was flagged as blacklisted by automated scanners, it is provided strictly as an informational link in a directory of lead sources and does not involve automated downloads or script execution.
  • [PROMPT_INJECTION]: The skill includes workflows for processing content from external websites to determine business fit, which represents a surface for indirect prompt injection.
  • Ingestion points: External domains are visited and summarized via AI as described in resources/templates/beginner-workflow.md.
  • Boundary markers: Not explicitly defined for the ingested summaries, though strict output constraints ('Only output B2B or B2C') are applied to the classification step.
  • Capability inventory: No high-risk capabilities such as file system writes, shell access, or administrative operations are connected to this data processing pipeline.
  • Sanitization: None detected on the ingested text. This exposure is inherent to the skill's function as an information extraction tool and does not indicate malicious intent.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 15, 2026, 08:56 PM
Security Audit — agent-trust-hub — list-building