sales-prospeo
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill recommends installing a supplementary tool using "npx skills add sales-skills/sales --skills sales-do". This is a vendor-owned resource used to extend the functionality of the agent.- [DATA_EXFILTRATION]: The skill documents the use of the Prospeo API at "https://api.prospeo.io". This is the intended functionality of the skill for data enrichment and search operations.- [PROMPT_INJECTION]: The skill contains instructions to append new knowledge to "references/learnings.md" and read it in future sessions, which is a surface for indirect prompt injection. * Ingestion points: "references/learnings.md" and user input. * Boundary markers: Absent. * Capability inventory: Reading and writing to local reference files. * Sanitization: Absent.
Audit Metadata