agentai

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: CRITICALPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface.
  • Ingestion points: The skill fetches untrusted data from the open web and social media via tools such as grab_web_text, get_linkedin_profile, and get_search_results defined in SKILL.md.
  • Boundary markers: Absent. The instructions do not provide delimiters or ignore-instructions for the external content retrieved.
  • Capability inventory: The skill possesses powerful capabilities including invoke_action, rest_call, and invoke_agent, which could be triggered by malicious instructions embedded in scraped data.
  • Sanitization: There is no evidence of filtering or validation of external data before processing.
  • [EXTERNAL_DOWNLOADS]: Malicious domain reference in metadata.
  • Evidence: The author domain Builder.org listed in SKILL.md metadata is flagged as blacklisted by automated URL reputation scanners.
  • [DATA_EXFILTRATION]: Potential for unauthorized data exposure.
  • Description: The skill provides extensive tools for extracting data from social profiles (LinkedIn, Twitter, Instagram, Bluesky) and performing person enrichment, which increases the risk of data exfiltration if the agent's logic is subverted.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 4, 2026, 04:37 PM
Security Audit — agent-trust-hub — agentai