lead-enrichment
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Uses
curlto perform API requests andpython3to parse the local~/.gooseworks/credentials.jsonfile for the API key.- [EXTERNAL_DOWNLOADS]: Communicates withapi.gooseworks.aito retrieve contact and company information from third-party enrichment services.- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external data. - Ingestion points: Responses from Hunter, Sixtyfour, and Fiber APIs (e.g., email verification and profile data).
- Boundary markers: None present to separate data from instructions.
- Capability inventory: Shell command execution via
curland file read access. - Sanitization: No sanitization or validation of the external API content is documented.- [SAFE]: All identified behaviors are consistent with the skill's stated purpose of lead enrichment and involve communication with the vendor's official infrastructure.
Audit Metadata