ICP Qualification Framework

Pass

Audited by Gen Agent Trust Hub on Jun 6, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill is composed entirely of markdown instructions and YAML metadata (SKILL.md). It does not include any executable scripts, binaries, or environment configurations.\n- [SAFE]: No indicators of prompt injection, obfuscation, or malicious data access were found. The skill defines business logic for lead processing that is inherently non-executable.\n- [INDIRECT_PROMPT_INJECTION]: The skill involves processing untrusted external inputs as part of its lead scoring functionality.\n
  • Ingestion points: The agent is instructed to evaluate 'form notes' and 'source pages' provided by leads (SKILL.md).\n
  • Boundary markers: There are no instructions defining delimiters or boundary markers for the external content being analyzed.\n
  • Capability inventory: The skill directs the agent to perform write operations to a CRM system to log qualification scores and reasoning (SKILL.md).\n
  • Sanitization: No specific sanitization or validation protocols for the external lead data are mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 6, 2026, 08:37 AM
Security Audit — agent-trust-hub — ICP Qualification Framework