data-enrichment
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for using Large Language Models (LLMs) like Claude and GPT-4 to scrape and process data from external websites, blog posts, and LinkedIn profiles for firmographic and technographic enrichment.
- Ingestion points: Pattern 1 (Website Data Extraction) and Pattern 2 (Semantic Contact Matching) specifically describe ingesting unstructured, third-party content into the agent context via API calls.
- Boundary markers: The provided instructions do not include the use of delimiters or specific instructions to the LLM to ignore potentially malicious embedded text within the scraped content.
- Capability inventory: The ingested data is intended to be used for CRM field updates, ICP scoring, and lead routing, meaning malicious content could influence business logic or downstream automated processes.
- Sanitization: There is no mention of sanitizing, filtering, or validating the external content before passing it to an LLM or storing it in a database.
Audit Metadata