post-conference-outreach
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from badge-scan notes and interpolates it into outreach messages, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: The agent reads the
notesfield from an uploaded "booth or badge-scan list" as specified in theTemperature (router)andM1sections of SKILL.md. - Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" headers when processing the ingested notes.
- Capability inventory: The skill has permissions to read CRM data (HubSpot, Attio, Salesforce) and stage outreach sequences on Email and LinkedIn channels.
- Sanitization: There is no explicit requirement for the agent to sanitize or filter the content of the booth notes before using them as a hook in the
M1email body. - Mitigation: The skill explicitly requires that all outreach is "queued for approval for a human" and states "Nothing auto-sends," which prevents automated execution of malicious payloads.
Audit Metadata