prospect-research
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection surface detected.
- Ingestion points: In Step 2, the skill scrapes live web data from company websites, engineering blogs, press releases, and job postings using search tools.
- Boundary markers: The instructions lack delimiters (like XML tags or triple quotes) or explicit warnings to ignore instructions that might be embedded in the scraped data.
- Capability inventory: The skill is capable of writing research files and updating the
account-brief.mdfile on the local filesystem, as well as performing subsequent tool calls based on the scraped findings. - Sanitization: There is no logic provided to sanitize, filter, or validate the content retrieved from external sources before it is processed by the agent and written to disk.
Audit Metadata