outbound-sequencer

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill metadata references the '@clawfu/mcp-skills' package as its MCP server. This package is an external dependency hosted on a third-party registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves taking user-provided data (e.g., target persona, value proposition) to generate outbound sequences, creating a surface for indirect prompt injection if the inputs contain malicious instructions.
  • [NO_CODE]: The skill consists entirely of instructional markdown and metadata, with no internal scripts or binary executables provided within the skill package.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 08:26 PM
Security Audit — agent-trust-hub — outbound-sequencer