lead-enrichment

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Uses curl to perform API requests and python3 to parse the local ~/.gooseworks/credentials.json file for the API key.- [EXTERNAL_DOWNLOADS]: Communicates with api.gooseworks.ai to retrieve contact and company information from third-party enrichment services.- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external data.
  • Ingestion points: Responses from Hunter, Sixtyfour, and Fiber APIs (e.g., email verification and profile data).
  • Boundary markers: None present to separate data from instructions.
  • Capability inventory: Shell command execution via curl and file read access.
  • Sanitization: No sanitization or validation of the external API content is documented.- [SAFE]: All identified behaviors are consistent with the skill's stated purpose of lead enrichment and involve communication with the vendor's official infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 02:15 PM
Security Audit — agent-trust-hub — lead-enrichment