handle-reply
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill performs expected outreach management tasks using the vendor's internal tools and standard CRM integrations.
- [COMMAND_EXECUTION]: The skill utilizes vendor-provided code execution tools to handle large JSON outputs and perform batch classification tasks using the pandas library.
- [PROMPT_INJECTION]: The skill processes inbound email content which constitutes an indirect prompt injection surface. Ingestion points: Email thread data retrieved from sequence tools (SKILL.md). Boundary markers: None explicitly defined in the instructions for input delimited filtering. Capability inventory: CRM modification via HubSpot tools, sequence updates via Swan tools, and local data processing via swan-execute-code (SKILL.md). Sanitization: No specific sanitization of the email body is described. The risk is neutralized by the mandatory human-in-the-loop requirement that requires explicit user approval before any communication is sent.
Audit Metadata