affiliate-recruitment-outreach
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to visit and verify external prospect websites during the qualification phase (Step 4 in SKILL.md). These untrusted third-party sites could contain malicious instructions intended to influence the agent's drafting process.
- Ingestion points: The agent ingests data from external URLs during the prospect verification (Step 4) and qualification (Step 2) phases.
- Boundary markers: The skill does not provide specific instructions to use delimiters or ignore instructions found within the content of external websites.
- Capability inventory: The agent generates structured recruitment plans and multi-touch email sequences using the information gathered from these sites.
- Sanitization: The workflow lacks explicit steps for sanitizing or filtering data retrieved from the web before it is interpolated into the generated outreach artifact.
Audit Metadata