territory-signal-digest

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from account lists provided in arguments and data retrieved via the Lusha API. This represents an attack surface for indirect prompt injection where malicious instructions could be embedded in external signals (e.g., news headlines or company descriptions).
  • Ingestion points: Account names/domains from $ARGUMENTS and signal data (news, hiring, intent) from the Lusha API connector.
  • Boundary markers: Absent; the skill does not explicitly instruct the agent to ignore instructions embedded in the retrieved signal data.
  • Capability inventory: The skill utilizes tools for company search and signal retrieval; no arbitrary command execution or file writing capabilities are present.
  • Sanitization: Not specified; the skill relies on the agent's default processing of tool outputs.
  • [EXTERNAL_DOWNLOADS]: The skill contains a reference to Lusha's official documentation and template library. This reference is to a well-known service and does not involve the execution of remote scripts or unverifiable dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 06:18 PM
Security Audit — agent-trust-hub — territory-signal-digest