reach-out
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow in
references/improve-outreach.mdwhere user feedback is summarized and stored as persistent instructions ('principles') in the skill's reference files. - Ingestion points: User reactions to draft outreach and strategy shifts are ingested via the procedure defined in
references/improve-outreach.md. - Boundary markers: The skill lacks explicit delimiters or instructions to treat user feedback as untrusted data, increasing the risk that the agent will follow malicious instructions embedded within the feedback.
- Capability inventory: The agent is given the capability to modify the
SKILL.mdfile and all files in thereferences/directory to store new rules. - Sanitization: The skill lacks sanitization instructions to filter or validate user feedback before it is promoted to a permanent instruction, which could lead to the persistence of malicious prompts that override safety guardrails.
Audit Metadata