pipeline-signal-review
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data provided through user arguments, which constitutes a potential injection surface.
- Ingestion points: External deal lists, account names, domains, and contact information are read from the
$ARGUMENTSobject inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" directives to encapsulate user-provided deal data when it is processed by the agent.
- Capability inventory: The skill utilizes specific tools for Lusha integration (
companies_searchand contact verification). It does not request access to shell execution, file system writes, or arbitrary network utilities. - Sanitization: No explicit sanitization or validation of the input strings (such as account names or deal stages) is specified in the workflow logic.
Audit Metadata