playbook-name-to-other-prospects

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from external lead-generation services within an AI prompt to filter and clean candidate names. This ingestion of untrusted external content represents a surface for indirect prompt injection, where malicious instructions could be embedded in profile headlines or titles. * Ingestion points: Candidate data is ingested via lookup tools in clay-workflow.md (Node 3) and clay-table.md (Column 2). * Boundary markers: The prompt template in SKILL.md uses structured labels and few-shot examples to provide context and isolate external data. * Capability inventory: The skill performs network lookups, AI judging, and pushes the final data to email sequencers. * Sanitization: The skill includes a name normalization formula in clay-table.md that strips non-alphabetic characters and prompt-level rules to remove credentials and symbols.
  • [DATA_EXFILTRATION]: The skill initiates network requests to external third-party providers (Prospeo and Icypeas) to retrieve employee information by domain. While these operations are necessary for the skill's primary purpose, they involve data transmission to services outside the standard whitelist.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 02:36 PM
Security Audit — agent-trust-hub — playbook-name-to-other-prospects