outreach-builder
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, including LinkedIn profiles and company records, which introduces a vulnerability surface for indirect prompt injection.
- Ingestion points: Data retrieved from
apollo_company_search,apollo_company_enrich,linkedin_web_v2_user_profile,linkedin_web_v2_company_profile, andagentbody_linkedin_emailis processed by the agent (defined in SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or specific markers to separate untrusted external content from system instructions.
- Capability inventory: The skill utilizes a gateway (
sandbase_call_tool) to read from external platforms and verify email addresses. It does not appear to possess file-write or arbitrary command execution capabilities. - Sanitization: There is no mention of sanitization, filtering, or validation of the content retrieved from external sources before it is synthesized into a response.
Audit Metadata