cold-email
Warn
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions to explicitly suppress standard AI behavior, prohibiting warnings, notes, or disclaimers ('No warnings, notes, or disclaimers. Stick to requested output.'). This is a common tactic used to bypass or conceal safety guardrails and transparency messages.
- [PROMPT_INJECTION]: The 'Mandatory Content Standards' require a minimum of 1,500 words per output, which is inconsistent with the later instruction that email bodies should be under 75 words. This contradictory requirement for extreme length for a short-form task can lead to resource exhaustion or confusion of the model's logic.
- [PROMPT_INJECTION]: The skill processes untrusted user input and potentially external company URLs without defining boundary markers or instructions to ignore embedded commands. This creates a surface for indirect prompt injection. Ingestion points: User-provided product details and company URLs (SKILL.md). Boundary markers: Absent. Capability inventory: Automated generation of email copy. Sanitization: Absent.
Audit Metadata