prospect-to-outreach

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data from Lusha's API (contact profiles, company news, and hiring signals) to personalize email drafts. This represents a potential indirect prompt injection surface if the retrieved data contains malicious instructions.
  • Ingestion points: Data entering the context via prospecting_contact_search and signals_companies_get in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters (e.g., XML tags or triple quotes) to isolate the retrieved Lusha data from the generation prompt.
  • Capability inventory: The skill has the capability to write to the user's environment using the gmail.create_draft tool.
  • Sanitization: There are no explicit instructions to sanitize or escape the external data before interpolation into the email drafts.
  • Mitigation: The risk is naturally mitigated by the skill's core architecture, which mandates that the agent only create drafts and explicitly forbids automatic sending, ensuring a human-in-the-loop review process.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to documentation and outreach playbooks on the official Lusha domain (lusha.com). These references are contextually appropriate for a skill built around Lusha's services and are considered safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:49 AM
Security Audit — agent-trust-hub — prospect-to-outreach