lead-research-assistant

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate instructions for identifying and qualifying sales leads. No evidence of credential theft, obfuscated commands, or malicious persistence was found across the skill's instructions.\n- [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection attack surface by instructing the agent to analyze user-provided repositories or codebases to gain business context.\n
  • Ingestion points: The agent is instructed to analyze the product's 'codebase' or 'source code directory' to identify features and target markets.\n
  • Boundary markers: The skill lacks explicit instructions for the agent to use delimiters or to disregard embedded instructions within the analyzed codebase files.\n
  • Capability inventory: The skill utilizes file system access (to read the codebase) and potential web search capabilities to perform its lead research functions; no subprocess execution or direct network exfiltration logic is defined within the skill.\n
  • Sanitization: There is no mention of sanitizing, escaping, or validating the content found within the codebase before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 03:18 AM
Security Audit — agent-trust-hub — lead-research-assistant