warm-intro-intelligence

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from multiple external and internal sources. \n- Ingestion points: The agent scrapes LinkedIn posts using Apify actors, performs web research for co-mentions in news and panels, and analyzes call transcripts from tools like Gong or Fireflies, as described in Step 7 of SKILL.md and references/node-registry-and-edge-discovery.md. \n- Boundary markers: There are no defined delimiters or specific instructions for the agent to isolate or ignore potentially malicious commands embedded within the retrieved external data. \n- Capability inventory: The skill has high-privilege read access to sensitive corporate data (CRM records, meeting transcripts, employee rosters) and the ability to send messages to users via Slack and chat. \n- Sanitization: The skill lacks explicit sanitization or validation logic for external content before it is processed or presented to the user. \n- [EXTERNAL_DOWNLOADS]: The skill utilizes well-known external services and tools, such as Apify actors (e.g., harvestapi/linkedin-company-employees), to perform data extraction and enrichment tasks necessary for mapping professional networks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 12:17 AM
Security Audit — agent-trust-hub — warm-intro-intelligence