follow-up-email-sequence-writer

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: CRITICALPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from HubSpot (emails, notes, and engagements) to generate email drafts.
  • Ingestion points: SKILL.md (Workflow Step 1: reading contact/company engagements, last messages, and discussion notes).
  • Boundary markers: Absent. No specific delimiters or instructions to ignore embedded content in retrieved data are used in the workflow.
  • Capability inventory: Limited to text generation (drafting email sequences). The skill does not possess tools for file system access, network requests, or automated email sending.
  • Sanitization: Absent. There is no evidence of filtering or validation of the content retrieved from HubSpot engagements before it is processed.
  • [NO_CODE]: The skill consists entirely of instructional markdown and metadata. No executable scripts, binaries, or automated command-line operations were detected.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 4, 2026, 04:37 PM
Security Audit — agent-trust-hub — follow-up-email-sequence-writer