lifecycle-stage-stagnation-scanner

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: CRITICAL
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown documentation and natural language instructions. It does not contain any shell scripts, Python code, Node.js packages, or binaries.
  • [DATA_EXFILTRATION]: There are no network-capable commands (e.g., curl, wget) or external API calls defined in the skill. Data processing is restricted to the connected HubSpot environment and local report generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from HubSpot contacts, which represents a potential injection surface.
  • Ingestion points: HubSpot contact records, engagement history, and lifecycle metadata (SKILL.md).
  • Boundary markers: Absent; the instructions do not specify delimiters for external data.
  • Capability inventory: Read-only data aggregation and report drafting. No file-writing or command execution capabilities exist.
  • Sanitization: None specified for the ingested CRM data.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 4, 2026, 04:37 PM
Security Audit — agent-trust-hub — lifecycle-stage-stagnation-scanner