lead-scoring-model

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data sources which could be used to influence agent behavior through indirect prompt injection.\n
  • Ingestion points: The skill ingests CRM exports, historical win/loss datasets, and current lead lists (CSV/text) as defined in SKILL.md and references/inputs.md.\n
  • Capability inventory: The agent has access to Bash, Write, and WebFetch tools to perform data science analysis and generate files, which could be exploited if malicious payloads are embedded in the ingested data.\n
  • Boundary markers: The instructions do not specify the use of delimiters or specific prompts to ignore instructions within the ingested data files.\n
  • Sanitization: There is no mention of data validation, escaping, or sanitization of the CRM/CSV content before it is passed to shell tools for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — lead-scoring-model