posthog-onboarding-lead-research

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from several external sources to perform research and draft outreach, creating a surface for potential injection attacks.
  • Ingestion points: Data is ingested from user-provided referral context in SKILL.md and from external sources via Vitally MCP tools (get_account_notes, get_account_conversations) and Granola meeting note queries.
  • Boundary markers: The instructions lack explicit requirements for using delimiters or 'ignore embedded instructions' warnings when processing untrusted text.
  • Capability inventory: The skill utilizes web search capabilities and multiple CRM data retrieval tools via Vitally MCP.
  • Sanitization: There are no documented steps for sanitizing, filtering, or validating external content before it is processed by the agent to influence lead qualification and outreach drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:47 AM
Security Audit — agent-trust-hub — posthog-onboarding-lead-research