gtm
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external prospect websites, which is a vector for indirect prompt injection.\n
- Ingestion points: The
references/research.mdplaybook instructs the agent to crawl 3–5 key pages of prospect sites (About, Services, Contact, Blog, etc.) to extract firmographics and tech context.\n - Boundary markers: The agent is required to establish an Ideal Customer Profile (ICP) before research begins and must mark all unverified fields as assumptions.\n
- Capability inventory: According to the frontmatter and
agents/openai.yaml, the agent has access tobash,run_command,write_to_file,replace_file_content, andview_file.\n - Sanitization: The skill mandates the use of confidence levels (HIGH, MEDIUM, LOW) for all data and requires an 'Unverified' section for inferred or third-party data to prevent the agent from treating untrusted external content as definitive fact.
Audit Metadata