call-list

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, creating a potential attack surface.
  • Ingestion points: The skill retrieves correspondence from email accounts (e.g., Yandex 360) and lead data from CRM systems (e.g., Bitrix24, amoCRM) in Step 1.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate external email content or to prevent the agent from following instructions potentially hidden within those messages.
  • Capability inventory: The skill utilizes Bash, WebFetch, and Read tools. It has the capability to generate email drafts and create calendar entries.
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation of the email text before it is used to generate talking points or follow-up messages.
  • Mitigation: The skill includes explicit "Approval Gates" that require human confirmation before sending any emails, creating calendar events, or modifying CRM data, which significantly reduces the risk of autonomous exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:25 PM
Security Audit — agent-trust-hub — call-list