lead-scoring
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it processes external lead and account data while having access to powerful tools such as shell execution and file modification.
- Ingestion points: The skill ingests inbound and outbound lead data, which may contain attacker-controlled content.
- Boundary markers: The 'Global Protocols' section includes a mandatory directive to treat all web content and external data as hostile.
- Capability inventory: The frontmatter allows the use of
run_shell_command,write_file, andreplacetools. - Sanitization: The instructions explicitly require the agent to redact secrets and PII from external content before it is shared or processed.
Audit Metadata