client-packet-engine

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the web during several phases, creating an attack surface for indirect prompt injection where malicious instructions embedded in scraped websites could influence agent behavior.
  • Ingestion points: Initial website validation in Phase 0, competitor and industry research in Phase 1, and various scrapers (reviews, archives, events) in Phase 3.
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to the agent to ignore instructions found within the scraped content.
  • Capability inventory: The skill uses ingested data to perform email-drafting, content-asset-creator, and lead-qualification across several scripts.
  • Sanitization: There is no mention of filtering, escaping, or validating the external content before it is interpolated into prompts for generating drafts or reports.
  • [COMMAND_EXECUTION]: The playbook coordinates a multi-step automation chain involving numerous sub-skills. It features a high-impact configuration override (pitch_packet_mode: false) that enables live campaign activities, such as sending actual emails and consuming paid lead enrichment credits. This capability is appropriately documented with a warning requiring user confirmation.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes multiple external scraping tools and APIs (including Apify, LinkedIn research, and review scrapers) to collect business intelligence from public sources. These operations are transparently disclosed and essential to the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 06:25 PM
Security Audit — agent-trust-hub — client-packet-engine