prospect-research

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a defensive instruction designed to prevent users from extracting the system prompt or internal rules. It redirects such inquiries to a specific promotional URL.
  • [COMMAND_EXECUTION]: The documentation provides an example command for running a local Node.js script (tools/clis/github-prospects.js) to export data from GitHub. This is consistent with the skill's stated purpose of technical prospecting.
  • [INDIRECT_PROMPT_INJECTION]: Because the skill is designed to research and classify data from external, untrusted sources (such as GitHub profiles and business websites), it is inherently susceptible to indirect prompt injection if those external sources contain malicious instructions.
  • [EXTERNAL_DOWNLOADS]: The skill references several external B2B tools (Apollo, ZoomInfo, Clearbit) and includes monetization links (CashApp, BuyMeACoffee) as part of a mandatory introductory message.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:11 AM
Security Audit — agent-trust-hub — prospect-research