account-scoring
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection in the score-account workflow within plays/score-accounts.ts. 1. Ingestion points: Untrusted data from account names and domains is interpolated directly into the agent's prompt. 2. Boundary markers: Absent; no delimiters are used to separate account data from instructions. 3. Capability inventory: The agent can perform business database lookups and firmographic enrichment, and the workflow can write to HubSpot. 4. Sanitization: Absent; no input filtering is implemented.
- [EXTERNAL_DOWNLOADS]: The skill installation process downloads the @cargo-ai/cli package and references resources from the getcargohq organization. These are official platform tools and vendor-provided cookbooks required for the skill's deployment and operation.
Audit Metadata