real-estate-outreach-copywriter
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted lead data without using boundary markers or sanitization.
- Ingestion points: External lead segment details such as nationality, budget, and property interest are processed during the brief intake phase as described in SKILL.md.
- Boundary markers: No delimiters, tags, or specific warnings are present to isolate external lead data from the agent's core instructions.
- Capability inventory: The skill focuses on text generation for outreach messages and does not display access to high-risk tools or shell execution capabilities in SKILL.md or the run.sh script.
- Sanitization: No input validation, escaping, or filtering is specified to handle potentially malicious instructions embedded in the lead data.
Audit Metadata