gtm-plays-11
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions involve processing untrusted external data, which creates a surface for indirect prompt injection.\n
- Ingestion points: The agent is instructed to extract LinkedIn profile data (Play 2) and scrape negative reviews from G2 or Capterra (Play 8) as described in
SKILL.md.\n - Boundary markers: The instructions do not provide specific delimiters or warnings to ignore commands that might be embedded within the ingested external content.\n
- Capability inventory: The skill is intended to facilitate reading external web content and generating outreach communications (emails/messages) based on that content.\n
- Sanitization: There is no mention of sanitizing or validating the retrieved data before it is processed by the agent.
Audit Metadata