skills/swan-gtm/gtm-skills/reach-out/Gen Agent Trust Hub

reach-out

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow in references/improve-outreach.md where user feedback is summarized and stored as persistent instructions ('principles') in the skill's reference files.
  • Ingestion points: User reactions to draft outreach and strategy shifts are ingested via the procedure defined in references/improve-outreach.md.
  • Boundary markers: The skill lacks explicit delimiters or instructions to treat user feedback as untrusted data, increasing the risk that the agent will follow malicious instructions embedded within the feedback.
  • Capability inventory: The agent is given the capability to modify the SKILL.md file and all files in the references/ directory to store new rules.
  • Sanitization: The skill lacks sanitization instructions to filter or validate user feedback before it is promoted to a permanent instruction, which could lead to the persistence of malicious prompts that override safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 01:27 PM
Security Audit — agent-trust-hub — reach-out