track-contact-job-changes

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of instructional markdown and reference files. It does not include any executable scripts (Python, JavaScript), shell scripts, or binary files. All operations are performed by the agent through abstracted tool calls according to the provided rules.
  • [PROMPT_INJECTION]: The skill processes data from external sources (CRM records, LinkedIn search results, work history APIs, and company enrichment services), which represents an indirect prompt injection surface. The analysis of this surface is as follows:
  • Ingestion points: CRM contact data (SKILL.md), LinkedIn-URL finder results, work-history source data, email lookup results, and company enrichment data (setup-checklist.md).
  • Boundary markers: Present. The skill explicitly mandates a human-in-the-loop review step ("Golden rule: propose, then confirm") where all changes must be approved by the operator before execution.
  • Capability inventory: CRM record updates and new account creation.
  • Sanitization: Present. The instructions require strict name validation (comparing external profile names against existing CRM records), domain normalization, and comparison of hard identifiers like LinkedIn company slugs to prevent data corruption or incorrect associations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 12:16 AM
Security Audit — agent-trust-hub — track-contact-job-changes