prospecting

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various external and untrusted sources, creating a vulnerability surface for instructions embedded in external content.
  • Ingestion points: Data is collected from official sites, registries, professional profiles, directories, public filings, job listings, technology observations, and event lists as defined in references/prospecting-system.md.
  • Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for the content retrieved from these external sources.
  • Capability inventory: The skill is limited to research and list generation. It does not contain code for subprocess execution, arbitrary file writes, or unauthorized network operations beyond reading sources.
  • Sanitization: There is no explicit instruction to sanitize, validate, or filter the content retrieved from external sources before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:55 AM
Security Audit — agent-trust-hub — prospecting