contact-hunter

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to gather and process data from a wide variety of external, untrusted sources. Malicious actors could place hidden instructions within these sources to influence the agent's behavior during extraction.
  • Ingestion points: Data is gathered from LinkedIn profiles, company 'About' and 'Leadership' pages, professional directories, and GitHub bios as defined in SKILL.md and references/search-queries.md.
  • Boundary markers: The instructions do not include specific delimiters or warnings for the agent to distinguish between its internal instructions and the potentially untrusted content being processed.
  • Capability inventory: The skill utilizes the agent's web browsing and search capabilities to read external data and format it into structured templates (CSV, JSON).
  • Sanitization: No sanitization, validation, or filtering mechanisms are prescribed for the content retrieved from external sources before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:01 PM
Security Audit — agent-trust-hub — contact-hunter