reply-handling

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (inbound cold email replies) to drive agent automation and decision-making.
  • Ingestion points: As described in the taxonomy and execution phases, the agent ingests raw text from prospect replies to categorize them into one of eight buckets.
  • Boundary markers: The prompt instructions and output templates do not define specific delimiters or instructions to treat inbound email content as untrusted data or to ignore potential instructions embedded within those replies.
  • Capability inventory: Based on the classification results, the agent has the capability to generate and send automated emails, modify CRM contact metadata (tags and status), and manage sequence automation (pausing or resuming outreach).
  • Sanitization: The skill lacks explicit guidance on sanitizing, filtering, or escaping content within email replies before it is used to influence the agent's logic or internal state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:47 PM
Security Audit — agent-trust-hub — reply-handling