email-personalization
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. (1) Ingestion points: Ingests LinkedIn posts and lead intelligence data from CSV/JSON files. (2) Boundary markers: No explicit boundary markers or instructions to disregard embedded commands are present in the processing logic. (3) Capability inventory: Spawns sub-agents and executes Python scripts for quality assurance. (4) Sanitization: There is no evidence of data validation or sanitization for the ingested content.
- [COMMAND_EXECUTION]: The skill provides a Python code block intended for the agent to execute as a quality check to filter for prohibited words and phrases in the output.
Audit Metadata