gtm-enrichment-smart

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs lead enrichment by coordinating calls to external data providers including Apollo, Hunter, and Abstract Company Enrichment via the Locus gateway, and a SELAT-native Twitter lookup. All network operations are consistent with the documented purpose of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to apollo.mpp.paywithlocus.com, hunter.mpp.paywithlocus.com, abstract-company-enrichment.mpp.paywithlocus.com, and catalog.selat.ai. These endpoints are used to fetch lead intelligence and are appropriate for a lead enrichment workflow.
  • [DATA_EXFILTRATION]: While lead data (emails and domains) is transmitted to external providers, this is the primary intended behavior of the skill and occurs over established payment-gated infrastructure (MPP on Tempo / Circle Gateway) as described in the documentation.
  • [PROMPT_INJECTION]: The skill defines a constrained execution environment via a machine-readable manifest (manifest.json), which prevents user-provided inputs or API responses from being interpreted as instructions for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 07:34 PM
Security Audit — agent-trust-hub — gtm-enrichment-smart