personalization-at-scale

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external sources, including user-provided prospect lists and content retrieved from LinkedIn activity or company news. This creates an attack surface where malicious instructions embedded in external content could attempt to influence the agent's behavior.
  • Ingestion points: SKILL.md (Workflow Step 1: Ingesting prospect lists; Step 3: Researching external signals from LinkedIn and news).
  • Boundary markers: The skill does not explicitly instruct the agent to use delimiters or sanitization patterns to isolate external content from the system prompt.
  • Capability inventory: The skill's capabilities are focused on research, text generation, and data export (CSV); it does not perform high-risk operations such as arbitrary command execution or unauthorized network exfiltration.
  • Sanitization: There are no defined mechanisms for filtering or escaping instructions that might be contained within the researched data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — personalization-at-scale