skills/melumuccu/ai/prospecting/Gen Agent Trust Hub

prospecting

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of ingesting and analyzing untrusted data from the web.
  • Ingestion points: The instructions direct the agent to read and process content from prospect websites via tools like Firecrawl and Browserbase, as well as social media posts, forum threads, and GitHub issues (references/demand-signals.md, references/local-prospecting.md).
  • Capability inventory: The agent processes this external content to extract "pain signals" and "buying triggers," which are then written to CSV files or chat tables.
  • Sanitization: While the skill mentions escaping values when generating HTML reports, it lacks explicit delimiters or instructions to prevent the agent from following malicious commands embedded within the external data it analyzes.
  • [EXTERNAL_DOWNLOADS]: The skill relies extensively on a large number of external B2B data providers and enrichment services.
  • Evidence: Integration and usage guidelines are provided for services including Apollo, ZoomInfo, Clearbit, Clay, Hunter, Snov, and Truelist.
  • Context: These are well-known technology services, and their use is consistent with the primary purpose of the skill.
  • [COMMAND_EXECUTION]: The skill utilizes a local shell command to execute a script for GitHub data extraction.
  • Evidence: In references/saas-prospecting.md, the agent is instructed to run node tools/clis/github-prospects.js to harvest data from GitHub stargazers and forks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 04:17 AM
Security Audit — agent-trust-hub — prospecting