handle-reply

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill performs expected outreach management tasks using the vendor's internal tools and standard CRM integrations.
  • [COMMAND_EXECUTION]: The skill utilizes vendor-provided code execution tools to handle large JSON outputs and perform batch classification tasks using the pandas library.
  • [PROMPT_INJECTION]: The skill processes inbound email content which constitutes an indirect prompt injection surface. Ingestion points: Email thread data retrieved from sequence tools (SKILL.md). Boundary markers: None explicitly defined in the instructions for input delimited filtering. Capability inventory: CRM modification via HubSpot tools, sequence updates via Swan tools, and local data processing via swan-execute-code (SKILL.md). Sanitization: No specific sanitization of the email body is described. The risk is neutralized by the mandatory human-in-the-loop requirement that requires explicit user approval before any communication is sent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 04:39 PM
Security Audit — agent-trust-hub — handle-reply