list-building

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various external and potentially untrusted sources, which could contain hidden instructions for the agent.\n
  • Ingestion points: The skill workflow involves processing data from "LinkedIn Sales Nav", "Apollo Search", "Google Maps scrapes", and "conference attendee lists" (SKILL.md, Phase 1).\n
  • Boundary markers: The instructions do not specify the use of delimiters or clear boundaries to differentiate between system instructions and data ingested from external prospect lists.\n
  • Capability inventory: The skill includes a local validation script scripts/check-output.py that reads the content of local files provided as command-line arguments.\n
  • Sanitization: There is no evidence of data sanitization or filtering to prevent the agent from executing instructions that might be embedded in the prospect data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:46 PM
Security Audit — agent-trust-hub — list-building