news-signal-outreach

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and analyzes content from arbitrary external sources (Step 1) to drive its workflow.
  • Ingestion points: The skill accepts URLs from articles, LinkedIn posts, and tweets in the news_input field and fetches the raw content for parsing.
  • Boundary markers: Absent. The instructions do not define specific delimiters or provide guidance to the agent to distinguish between the content of the news and its own operational instructions.
  • Capability inventory: The skill possesses significant capabilities, including performing web searches, identifying contacts via external tools (Apollo, LinkedIn), and drafting emails that are eventually passed to outreach platforms like Smartlead or Outreach.io.
  • Sanitization: Absent. There are no requirements to sanitize, filter, or escape the retrieved external content before it is interpolated into connection angles or email drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — news-signal-outreach