pre-conference-outreach
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external attendee lists and diverse CRM records, including emails and call transcripts, which could theoretically contain malicious instructions.
- Ingestion points: External attendee lists (name, company, title) and CRM data (emails, meeting notes, call transcripts, and deal history) are retrieved and processed to generate outreach hooks (SKILL.md).
- Boundary markers: The instructions rely on template placeholders for data interpolation but do not specify technical delimiters to isolate untrusted content from the agent's instructions.
- Capability inventory: The agent has the capability to write to the CRM (tagging companies and recording account memory) and to stage emails and LinkedIn messages for delivery (SKILL.md).
- Sanitization: The skill contains explicit safeguards requiring that every row is researched and every outgoing message is queued for human approval. The instructions state "Nothing auto-sends" and "Approval is always queued for a human," providing a robust manual sanitization and review step (SKILL.md, references/setup-customization-checklist.md).
Audit Metadata