gtm-lead-capture
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill provides instructions for the agent to act as a lead operations strategist, focusing on scoring and response automation using local project context.
- [DATA_EXPOSURE]: The skill manages files within the
data/gtm/directory. This is consistent with its stated purpose of capturing and scoring lead information and does not involve access to sensitive system directories or credentials. - [PROMPT_INJECTION]: The skill reads from several local data files and the
CLAUDE.mdfile to gather context. While this represents a surface for indirect prompt injection from data sources, the risk is negligible as the skill lacks high-privilege capabilities such as arbitrary shell execution or outbound network communication.
Audit Metadata