data-quality

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted contact and account lists provided by users, which creates a surface for indirect prompt injection attacks.
  • Ingestion points: Contact lists and account data provided via $ARGUMENTS in SKILL.md.
  • Boundary markers: Absent; there are no delimiters (such as XML tags or specific markers) defined to isolate the user-provided data from the agent's instructions.
  • Capability inventory: The skill uses the Lusha connector for data verification; it does not request file system access, shell execution, or arbitrary network capabilities.
  • Sanitization: Absent; the instructions do not include steps to validate or filter the input list for malicious instructions or hidden commands.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and playbooks from Lusha's official domain. Lusha is a well-known B2B data provider, and this reference is legitimate and safe for the skill's intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 06:43 AM
Security Audit — agent-trust-hub — data-quality