outreach-builder

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, including LinkedIn profiles and company records, which introduces a vulnerability surface for indirect prompt injection.
  • Ingestion points: Data retrieved from apollo_company_search, apollo_company_enrich, linkedin_web_v2_user_profile, linkedin_web_v2_company_profile, and agentbody_linkedin_email is processed by the agent (defined in SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or specific markers to separate untrusted external content from system instructions.
  • Capability inventory: The skill utilizes a gateway (sandbase_call_tool) to read from external platforms and verify email addresses. It does not appear to possess file-write or arbitrary command execution capabilities.
  • Sanitization: There is no mention of sanitization, filtering, or validation of the content retrieved from external sources before it is synthesized into a response.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:30 PM
Security Audit — agent-trust-hub — outreach-builder