prospect-to-outreach
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data from Lusha's API (contact profiles, company news, and hiring signals) to personalize email drafts. This represents a potential indirect prompt injection surface if the retrieved data contains malicious instructions.
- Ingestion points: Data entering the context via
prospecting_contact_searchandsignals_companies_getinSKILL.md. - Boundary markers: The instructions do not define specific delimiters (e.g., XML tags or triple quotes) to isolate the retrieved Lusha data from the generation prompt.
- Capability inventory: The skill has the capability to write to the user's environment using the
gmail.create_drafttool. - Sanitization: There are no explicit instructions to sanitize or escape the external data before interpolation into the email drafts.
- Mitigation: The risk is naturally mitigated by the skill's core architecture, which mandates that the agent only create drafts and explicitly forbids automatic sending, ensuring a human-in-the-loop review process.
- [EXTERNAL_DOWNLOADS]: The skill provides links to documentation and outreach playbooks on the official Lusha domain (
lusha.com). These references are contextually appropriate for a skill built around Lusha's services and are considered safe.
Audit Metadata