posthog-onboarding-lead-research
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from several external sources to perform research and draft outreach, creating a surface for potential injection attacks.
- Ingestion points: Data is ingested from user-provided referral context in
SKILL.mdand from external sources via Vitally MCP tools (get_account_notes,get_account_conversations) and Granola meeting note queries. - Boundary markers: The instructions lack explicit requirements for using delimiters or 'ignore embedded instructions' warnings when processing untrusted text.
- Capability inventory: The skill utilizes web search capabilities and multiple CRM data retrieval tools via Vitally MCP.
- Sanitization: There are no documented steps for sanitizing, filtering, or validating external content before it is processed by the agent to influence lead qualification and outreach drafts.
Audit Metadata