data-enrichment

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the agentcash package from the public NPM registry as part of its setup process.
  • [DYNAMIC_EXECUTION]: The workflow relies on npx agentcash@latest, which dynamically fetches and executes the most recent code from a remote registry at runtime, bypassing version pinning.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured and unstructured contact and company data from external third-party API endpoints, creating a potential surface for malicious instructions to influence the agent.
  • Ingestion points: Data is retrieved from multiple stableenrich.dev endpoints into the agent's context.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions potentially embedded in the API responses.
  • Capability inventory: The skill uses a CLI tool to perform network requests and data retrieval operations.
  • Sanitization: No sanitization or validation logic is specified for the data retrieved from the enrichment APIs before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:55 AM
Security Audit — agent-trust-hub — data-enrichment