stalled-deal-revival
Fail
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: CRITICALPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from HubSpot engagement history to generate diagnoses and outreach drafts.
- Ingestion points: Engagement history, including notes and emails, is read from HubSpot as described in
SKILL.md. - Boundary markers: No delimiters or instructions are provided to the agent to ignore potentially malicious content embedded within the HubSpot data.
- Capability inventory: The agent generates outreach drafts based on the processed data; an attacker could potentially influence the tone or content of these drafts by injecting instructions into HubSpot notes.
- Sanitization: The workflow does not describe any sanitization, filtering, or validation of the ingested engagement history.
- [PROMPT_INJECTION]: The metadata field
authorlists 'Builder.org', a domain flagged as malicious by automated URL reputation scanners. While the skill is currently purely instructional and does not perform network requests or execute code from this domain, the association with a blacklisted domain represents a reputation risk.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata