gtm-prospecting
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from external-facing sources such as inbound lead files and project-level documentation, which presents a surface for indirect prompt injection.\n
- Ingestion points: The agent reads data from
data/gtm/prospects/inbound/(sourced from web engagement) and the project'sCLAUDE.mdfile.\n - Boundary markers: There are no explicit instructions or delimiters defined to isolate untrusted content from these files.\n
- Capability inventory: The agent has permissions to read and write prospect data and business context files in the project directory.\n
- Sanitization: No sanitization or verification process for the ingested content is specified.
Audit Metadata