job-change-play
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests data from external sources such as LinkedIn notifications, CRM enrichment triggers, and Sales Navigator alerts to generate sales playbooks. The absence of sanitization or boundary markers for this untrusted data creates a surface for indirect prompt injection, although the risk is mitigated by the skill's limited capabilities. 1. Ingestion points: LinkedIn, Apollo, and LeadMagic job change signals as described in SKILL.md. 2. Boundary markers: None identified in the provided instructions. 3. Capability inventory: Local markdown file generation and execution of a structural validation script (scripts/check-output.py). 4. Sanitization: No explicit filtering or escaping of external content is specified.
Audit Metadata