warm-intro-intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill requires access to highly sensitive business communication data, including CRM records, email threads, and call transcripts from platforms such as Gong and Fireflies, to identify and compute professional relationship edges.
- [EXTERNAL_DOWNLOADS]: Skill documentation references the use of external third-party scraping services, specifically Apify actors, to gather LinkedIn employment history and build organizational rosters.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to the ingestion of untrusted external content.
- Ingestion points: Public LinkedIn posts and web research co-mentions are ingested into the agent context in
SKILL.md(Step 7) andreferences/node-registry-and-edge-discovery.md(Call transcripts and LinkedIn messages). - Boundary markers: The instructions do not define delimiters or explicit 'ignore' markers to separate untrusted external data from system instructions.
- Capability inventory: Capabilities are restricted to generating a chat-based output card for human review; the agent is explicitly prohibited from performing CRM writes or initiating outreach.
- Sanitization: There is no description of content filtering or sanitization for the data ingested from external sources.
Audit Metadata