data-enrichment
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the agentcash package from the public NPM registry as part of its setup process.
- [DYNAMIC_EXECUTION]: The workflow relies on npx agentcash@latest, which dynamically fetches and executes the most recent code from a remote registry at runtime, bypassing version pinning.
- [INDIRECT_PROMPT_INJECTION]: The skill processes structured and unstructured contact and company data from external third-party API endpoints, creating a potential surface for malicious instructions to influence the agent.
- Ingestion points: Data is retrieved from multiple stableenrich.dev endpoints into the agent's context.
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions potentially embedded in the API responses.
- Capability inventory: The skill uses a CLI tool to perform network requests and data retrieval operations.
- Sanitization: No sanitization or validation logic is specified for the data retrieved from the enrichment APIs before it is processed by the agent.
Audit Metadata