contact-research
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes external data from community platforms and social profiles. However, the risk is mitigated by explicit instructions to avoid speculation and fabrication of data (Step 1 and Step 3). Ingestion points: Common Room data fields such as activity history and Spark summaries. Boundary markers: The skill uses structured templates for output but does not define explicit delimiters for ingested data. Capability inventory: The skill is restricted to information retrieval and display; no command execution or unauthorized file access capabilities are present. Sanitization: Prompt-level instructions mandate accuracy and non-fabrication.- [DATA_EXFILTRATION]: The skill is designed to retrieve and display professional PII (names, emails, titles, and social handles). This behavior is the primary intended function of the contact research tool and utilizes authorized service integrations.- [SAFE]: No obfuscation, persistence mechanisms, or unauthorized privilege escalation attempts were detected. The skill instructions follow best practices for ensuring data integrity during agent operations.
Audit Metadata