discovery-call-prep
Fail
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: CRITICALPROMPT_INJECTIONDATA_EXFILTRATIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The metadata field 'author' lists 'Builder.org', which contradicts the identified author 'OnStartups'. This domain is also flagged by automated security scans as having a poor reputation, suggesting deceptive metadata practices.
- [PROMPT_INJECTION]: The skill ingests untrusted data from call transcripts and web searches, making it vulnerable to indirect prompt injection where malicious instructions embedded in the data could manipulate the agent's output. Ingestion points: Processes external call transcripts and web research results during prep and post-call modes. Boundary markers: The skill lacks delimiters or instructions for the agent to ignore or isolate instructions potentially contained within the external transcripts or search results. Capability inventory: Reads and summarizes HubSpot contact/company/deal data and performs web searches. Sanitization: No sanitization or validation of external content is documented.
- [DATA_EXFILTRATION]: The skill requests access to sensitive HubSpot account data, including contact information and firmographics. While necessary for the skill's functionality, it involves processing sensitive business and personal identifiable information (PII).
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata