inbound-lead-enrichment

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill manages sensitive lead data (emails, LinkedIn profiles) and accesses external CRM systems such as HubSpot and Salesforce. This access is required for lead enrichment and involves reading from/writing to client-specific directories (clients/).
  • [EXTERNAL_DOWNLOADS]: The workflow incorporates data retrieval from well-known third-party services including Apollo, Crunchbase, and Apify (LinkedIn scraping). These are recognized tools in the sales automation industry.
  • [COMMAND_EXECUTION]: The skill performs file system operations to manage configuration JSON and output enriched lead data in CSV format. These operations are scoped to the clients/ directory.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data retrieved from the web (e.g., company descriptions and LinkedIn activity). This is an inherent risk of web-research capabilities, but the skill itself does not contain malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — inbound-lead-enrichment