contact-enrichment-on-create

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill metadata references 'Builder.org' as the author. This domain has been identified as malicious by automated scanners, posing a risk of reputation damage or exposure to malicious infrastructure for users interacting with the skill's documentation or metadata.
  • [PROMPT_INJECTION]: The skill processes untrusted contact and company data from HubSpot without explicit sanitization or boundary markers, creating a surface for indirect prompt injection attacks where malicious content in a record could influence agent behavior.
  • Ingestion points: Retrieving contact and company records from HubSpot and the web (SKILL.md).
  • Boundary markers: No specific delimiters or instructions are provided to the agent to distinguish between trusted instructions and untrusted data from the external records.
  • Capability inventory: The skill reads from HubSpot APIs and external web signals to generate display cards.
  • Sanitization: No evidence of data validation, escaping, or sanitization is present for the ingested contact information.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 4, 2026, 04:37 PM
Security Audit — agent-trust-hub — contact-enrichment-on-create