membership-prospect-followup

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the internal_note field of prospect records retrieved via the classic_get_prospect tool. This creates a surface for indirect prompt injection attacks where instructions embedded in notes could influence the agent's behavior during triage or update operations.
  • Ingestion points: The classic_get_prospect tool returns internal_note and signup metadata used for analysis (referenced in SKILL.md).
  • Boundary markers: Absent. The skill instructions do not define delimiters or provide guidance to ignore instructions embedded within the prospect notes.
  • Capability inventory: The skill has write access via classic_update_prospect_note and suggests integration with other tools like membership-push-broadcast and membership-internal-subscription-grant.
  • Sanitization: Absent. There is no specified logic for escaping, filtering, or validating the content of the notes before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:57 PM
Security Audit — agent-trust-hub — membership-prospect-followup