reply-handling

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and act upon untrusted external data from inbound cold email replies.\n
  • Ingestion points: Data enters the agent context through prospect replies which are classified into an 8-category taxonomy in SKILL.md and references/reply-taxonomy.md.\n
  • Boundary markers: The skill does not define explicit delimiters or boundary markers to isolate untrusted reply content from the agent's internal instructions or system prompt.\n
  • Capability inventory: The skill facilitates automated email responses and CRM activity logging via well-known external platforms such as Smartlead, Instantly, Salesforge, and Apollo.\n
  • Sanitization: No specific instructions are provided for escaping or validating external content (such as names or body text) before it is interpolated into automated reply templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 03:21 PM
Security Audit — agent-trust-hub — reply-handling