trigger-based-outbound
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious code, obfuscation, or data exfiltration patterns were detected in the skill files.
- [NO_CODE]: The skill contains only documentation and instructional content in Markdown format; no executable scripts or binaries are present.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies external account events and evidence as input. While this constitutes an untrusted data ingestion surface, the risk is mitigated by explicit instructions requiring human verification of all data and human approval of all drafted messages before execution. Evidence Chain: 1. Ingestion points: Event, source, and account evidence capture (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Drafting outreach messages and recording outcome records. 4. Sanitization: Mandatory human-in-the-loop review for all drafted messages and verification of source data.
Audit Metadata