list-building
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various external and potentially untrusted sources, which could contain hidden instructions for the agent.\n
- Ingestion points: The skill workflow involves processing data from "LinkedIn Sales Nav", "Apollo Search", "Google Maps scrapes", and "conference attendee lists" (SKILL.md, Phase 1).\n
- Boundary markers: The instructions do not specify the use of delimiters or clear boundaries to differentiate between system instructions and data ingested from external prospect lists.\n
- Capability inventory: The skill includes a local validation script
scripts/check-output.pythat reads the content of local files provided as command-line arguments.\n - Sanitization: There is no evidence of data sanitization or filtering to prevent the agent from executing instructions that might be embedded in the prospect data.
Audit Metadata