prospect-to-pipeline
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill processes professional contact details such as email addresses and phone numbers. It mitigates exposure risks by explicitly requiring the agent to mask sensitive information (e.g., initials only, masked phone digits) in the final response.
- [REMOTE_CODE_EXECUTION]: The skill retrieves enrichment data from Lusha, which is a well-known B2B data provider. This is a legitimate integration for the skill's stated prospecting purpose and does not involve the execution of untrusted remote code.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external signals from news and buying scoops to personalize drafts. (1) Ingestion points: Step 5 news and scoops. (2) Boundary markers: Absent. (3) Capability inventory: Drafting messages and searching Lusha. (4) Sanitization: Absent. This represents a low-risk ingestion surface because the data is used solely for text generation and does not influence executable commands.
Audit Metadata