lead-research-assistant
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from the local filesystem and external websites to identify leads. This creates a surface for indirect prompt injection where hidden instructions in external content could influence the agent's behavior. * Ingestion points: Local repository files and web search results. * Boundary markers: The instructions do not define specific delimiters for untrusted data. * Capability inventory: The agent possesses file-reading and web-searching capabilities. * Sanitization: No explicit content sanitization or validation steps are outlined.
- [NO_CODE]: The skill consists only of instructions in SKILL.md and does not include any executable scripts or binary files.
Audit Metadata