reply-handling
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and act upon untrusted external data from inbound cold email replies.\n
- Ingestion points: Data enters the agent context through prospect replies which are classified into an 8-category taxonomy in SKILL.md and references/reply-taxonomy.md.\n
- Boundary markers: The skill does not define explicit delimiters or boundary markers to isolate untrusted reply content from the agent's internal instructions or system prompt.\n
- Capability inventory: The skill facilitates automated email responses and CRM activity logging via well-known external platforms such as Smartlead, Instantly, Salesforge, and Apollo.\n
- Sanitization: No specific instructions are provided for escaping or validating external content (such as names or body text) before it is interpolated into automated reply templates.
Audit Metadata