cold-outreach-board

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No prompt injection or bypass patterns were detected. The instructions focus on guiding the agent to ask clarifying questions and route user problems to specific marketing frameworks. The "CRITICAL INSTRUCTION" section is a benign directive to ensure personalized output rather than an attempt to override safety protocols.
  • [DATA_EXFILTRATION]: No sensitive file paths, credential patterns, or network exfiltration commands (such as curl or wget) were found. The skill does not instruct the agent to access or transmit user data to external servers.
  • [REMOTE_CODE_EXECUTION]: The skill consists entirely of markdown text instructions and does not contain any code snippets, shell commands, or package installation steps that could lead to remote code execution.
  • [COMMAND_EXECUTION]: There are no patterns of subprocess spawning, system calls, or shell command execution. The skill does not utilize dynamic context injection (!command syntax).
  • [OBFUSCATION]: No obfuscated content, such as Base64, hex encoding, zero-width characters, or homoglyphs, was detected. The text is plain, readable markdown.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process user-provided context about their sales challenges. While this represents a standard data ingestion surface, the skill includes boundary-setting instructions (requiring clarifying questions before generating output) which mitigates accidental obedience to malicious input embedded in user descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 02:29 PM
Security Audit — agent-trust-hub — cold-outreach-board