prospect-investigation
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill researches and processes information from external websites, job postings, and news sources to identify leads. This ingestion of untrusted data presents a potential surface for indirect prompt injection if the external content contains malicious instructions designed to influence the agent's behavior.
- Ingestion points: External data sources including company websites, news articles, and job boards identified during the research phase (
SKILL.md). - Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded within the retrieved lead information.
- Capability inventory: The skill is limited to research, scoring, and formatting; it does not explicitly use network exfiltration tools or system-level command execution.
- Sanitization: There are no instructions for sanitizing or filtering the content retrieved from external sources before it is processed by the agent.
Audit Metadata