leaked-demand-recovery
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external sources (mailbox threads, chat transcripts, and lead forms) to draft recovery messages. This creates a surface for indirect prompt injection where malicious content within those communications could influence the agent's drafted output.
- Ingestion points:
SKILL.md(Step 2 and 4) andreferences/leak-map.mdidentify ingestion of mailbox history, chat transcripts, and recorder notes. - Boundary markers: The instructions lack explicit delimiters or instructions for the agent to disregard embedded commands within the ingested data.
- Capability inventory: The skill reads from communication systems and generates text drafts.
- Sanitization: No sanitization or escaping of the retrieved external content is specified before interpolation into drafts.
Audit Metadata