crm-data-enrichment

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill is entirely instructional and does not contain any executable scripts, configuration code, or external software dependencies.
  • [PROMPT_INJECTION]: The skill's primary workflow involves processing data from untrusted external environments, creating a surface for indirect prompt injection. * Ingestion points: Untrusted data enters the context from company websites, LinkedIn profiles, SEC filings, and job postings during the sourcing phase. * Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions to isolate untrusted content. * Capability inventory: No code execution, filesystem access, or network capabilities are present within the skill's own logic. * Sanitization: The skill suggests confidence scoring and cross-referencing for accuracy, but does not include technical sanitization or filtering of the external data to prevent injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 08:23 AM