networking-outreach
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the web and LinkedIn during target research.
- Ingestion points: Content is pulled from LinkedIn URLs, profile screenshots, and web searches (Mode 2, Steps 1 and 2).
- Boundary markers: The instructions lack explicit delimitation or directives to ignore instructions that might be embedded in target profiles.
- Capability inventory: The skill reads personal and brand strategy files from the local workspace and writes generated content to local draft files.
- Sanitization: No validation or sanitization is performed on the ingested external content.
- [NO_CODE]: The skill consists strictly of markdown instructions and does not contain any executable scripts or code dependencies.
Audit Metadata