lead-triage

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external leads which could contain hidden instructions intended to manipulate the agent's prioritization or drafting behavior.
  • Ingestion points: Untrusted data is ingested from ~~crm (specifically lead notes and company descriptions) and ~~почта (the content of previous email threads).
  • Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings to prevent the model from obeying instructions found within lead data.
  • Capability inventory: The skill generates prioritized summaries and email drafts. However, safety is mitigated by strict rules preventing the agent from sending emails, creating calendar events, or changing CRM statuses autonomously.
  • Sanitization: There is no explicit requirement for the agent to sanitize or filter out potentially malicious prose from lead records before processing them for scoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:25 PM
Security Audit — agent-trust-hub — lead-triage