post-conference-outreach

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from badge-scan notes and interpolates it into outreach messages, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: The agent reads the notes field from an uploaded "booth or badge-scan list" as specified in the Temperature (router) and M1 sections of SKILL.md.
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" headers when processing the ingested notes.
  • Capability inventory: The skill has permissions to read CRM data (HubSpot, Attio, Salesforce) and stage outreach sequences on Email and LinkedIn channels.
  • Sanitization: There is no explicit requirement for the agent to sanitize or filter the content of the booth notes before using them as a hook in the M1 email body.
  • Mitigation: The skill explicitly requires that all outreach is "queued for approval for a human" and states "Nothing auto-sends," which prevents automated execution of malicious payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:34 AM
Security Audit — agent-trust-hub — post-conference-outreach