gtm-prospecting

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from external-facing sources such as inbound lead files and project-level documentation, which presents a surface for indirect prompt injection.\n
  • Ingestion points: The agent reads data from data/gtm/prospects/inbound/ (sourced from web engagement) and the project's CLAUDE.md file.\n
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate untrusted content from these files.\n
  • Capability inventory: The agent has permissions to read and write prospect data and business context files in the project directory.\n
  • Sanitization: No sanitization or verification process for the ingested content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 12:09 AM
Security Audit — agent-trust-hub — gtm-prospecting