gtm-outbound
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security threats detected. The skill follows best practices for its intended purpose of marketing automation and outreach orchestration within a localized environment.
- [DATA_EXFILTRATION]: The skill accesses project-specific configuration and prospect data from the local 'data/gtm/' directory. This behavior is considered safe and appropriate as it is restricted to the skill's defined workspace and does not involve network exfiltration.
- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes external data from prospect enrichment files and interpolates it into message prompts. However, this is categorized as safe because the skill lacks dangerous capabilities such as network access or shell execution, and the data is sourced from local project files. Ingestion points: 'data/gtm/prospects/enriched/', 'data/gtm/messaging_framework.json'. Capability inventory: File writes to 'data/gtm/outbound/'. Boundary markers: None. Sanitization: None.
Audit Metadata