contact-enrichment-on-create
Fail
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill metadata references 'Builder.org' as the author. This domain has been identified as malicious by automated scanners, posing a risk of reputation damage or exposure to malicious infrastructure for users interacting with the skill's documentation or metadata.
- [PROMPT_INJECTION]: The skill processes untrusted contact and company data from HubSpot without explicit sanitization or boundary markers, creating a surface for indirect prompt injection attacks where malicious content in a record could influence agent behavior.
- Ingestion points: Retrieving contact and company records from HubSpot and the web (SKILL.md).
- Boundary markers: No specific delimiters or instructions are provided to the agent to distinguish between trusted instructions and untrusted data from the external records.
- Capability inventory: The skill reads from HubSpot APIs and external web signals to generate display cards.
- Sanitization: No evidence of data validation, escaping, or sanitization is present for the ingested contact information.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata