agentai
Fail
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: CRITICALPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface.
- Ingestion points: The skill fetches untrusted data from the open web and social media via tools such as
grab_web_text,get_linkedin_profile, andget_search_resultsdefined inSKILL.md. - Boundary markers: Absent. The instructions do not provide delimiters or ignore-instructions for the external content retrieved.
- Capability inventory: The skill possesses powerful capabilities including
invoke_action,rest_call, andinvoke_agent, which could be triggered by malicious instructions embedded in scraped data. - Sanitization: There is no evidence of filtering or validation of external data before processing.
- [EXTERNAL_DOWNLOADS]: Malicious domain reference in metadata.
- Evidence: The author domain
Builder.orglisted inSKILL.mdmetadata is flagged as blacklisted by automated URL reputation scanners. - [DATA_EXFILTRATION]: Potential for unauthorized data exposure.
- Description: The skill provides extensive tools for extracting data from social profiles (LinkedIn, Twitter, Instagram, Bluesky) and performing person enrichment, which increases the risk of data exfiltration if the agent's logic is subverted.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata