news-signal-outreach
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and analyzes content from arbitrary external sources (Step 1) to drive its workflow.
- Ingestion points: The skill accepts URLs from articles, LinkedIn posts, and tweets in the
news_inputfield and fetches the raw content for parsing. - Boundary markers: Absent. The instructions do not define specific delimiters or provide guidance to the agent to distinguish between the content of the news and its own operational instructions.
- Capability inventory: The skill possesses significant capabilities, including performing web searches, identifying contacts via external tools (Apollo, LinkedIn), and drafting emails that are eventually passed to outreach platforms like Smartlead or Outreach.io.
- Sanitization: Absent. There are no requirements to sanitize, filter, or escape the retrieved external content before it is interpolated into connection angles or email drafts.
Audit Metadata