icp-scoring
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a Python script (
scripts/check-output.py) used for basic validation of the generated report. This script only performs string matching and length checks on a local file passed as an argument, which is a standard utility function. - [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. The skill mentions using LeadMagic APIs (Company Search and Technographics) as optional tools, which is consistent with the author's identity and the skill's primary purpose.
- [DATA_EXFILTRATION]: There are no network operations or sensitive file access patterns that suggest data exfiltration. The skill processes user-provided business data (such as target industries and tech stacks) to generate a scoring model locally.
- [PROMPT_INJECTION]: The instructions follow standard agent guidelines and do not attempt to bypass safety filters or override system prompts. The 'Authoritative Foundations' section serves as a knowledge base for business methodologies (SPICED, MEDDICC) rather than an injection vector.
- [SAFE]: The skill represents a legitimate business tool for ICP (Ideal Customer Profile) scoring, with clear documentation, logical weights, and appropriate quality checks. All referenced tools and naming conventions are consistent with the vendor LeadMagic.
Audit Metadata