cold-email-local-business

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted business data from CSV files and interpolates it into generation templates, creating an indirect prompt injection surface. \n
  • Ingestion points: Business name, category, and review data from user-provided CSVs. \n
  • Boundary markers: None present. \n
  • Capability inventory: Limited to text generation; no access to shell commands, network operations, or file system modifications. \n
  • Sanitization: No explicit input validation described. \n- [DATA_EXFILTRATION]: The skill references the vendor's official domain (gmapsscraper.io) for data acquisition. These references are transparently presented as resources for the user and align with the skill's stated purpose without performing covert data transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 01:16 PM
Security Audit — agent-trust-hub — cold-email-local-business