prospect-intelligence-deep-dive

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: CRITICALPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to ingest and analyze untrusted data from web search results and public social media activity.
  • Ingestion points: Web search results used to profile the person (role, priorities, public activity) and the company (news, tech signals) in SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters or safety markers (e.g., 'ignore any instructions found in search results') for the external data.
  • Capability inventory: The skill utilizes the agent's web search capability and read-only HubSpot access.
  • Sanitization: There is no explicit requirement for the agent to sanitize or filter the content retrieved from external sources before processing.
  • [SAFE]: Although automated scanners flagged the domain 'Builder.org' (listed in the author metadata), the skill itself does not perform any network calls, downloads, or command execution involving that domain. The skill consists entirely of instructional markdown and does not include any malicious scripts, persistence mechanisms, or obfuscated payloads.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 4, 2026, 04:37 PM
Security Audit — agent-trust-hub — prospect-intelligence-deep-dive