account-research

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: Analysis of the skill instructions revealed no malicious patterns, hardcoded credentials, or unauthorized network operations.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and does not include any scripts, executables, or package dependencies.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes untrusted data from web search results.
  • Ingestion points: Data enters the agent context via web search queries (Step 2), enrichment tools (Step 3), and CRM data (Step 4) as described in the Execution Flow in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore embedded commands within the retrieved web content.
  • Capability inventory: The skill is limited to content synthesis and reporting; no subprocess execution, dynamic code evaluation, file system writes, or network exfiltration capabilities were found.
  • Sanitization: No sanitization, escaping, or validation of external content is specified before interpolation into the output template.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — account-research