personalized-outbound-ab-test
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of markdown instructions for sales outreach workflows and quality control logic. It does not include executable code, shell scripts, or malicious command patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill outlines a process for ingesting external lead data to generate personalized content. While this creates a potential attack surface, the instructions incorporate extensive mitigation strategies:
- Ingestion points: Lead connection lists, CRM deal statuses, and enrichment data (current role, headline, recent activity) as described in
SKILL.md. - Boundary markers: The skill mandates a six-point "safety gate" and programmatic re-verification of all generated messages.
- Capability inventory: The workflow is limited to text generation and data comparison; no dangerous system capabilities like subprocess execution or network exfiltration are present.
- Sanitization: Instructions require "factual grounding" checks where references must trace back to retrieved data, alongside programmatic enforcement of length, vocabulary, and formatting constraints.
Audit Metadata