cold-outreach
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it requires the agent to ingest and act upon data from untrusted external sources.
- Ingestion points: Workflow Step 2 in
SKILL.mdinstructs the agent to research external recipient signals from sources such as company pages, filings, job posts, and public writing. - Boundary markers: The skill does not prescribe the use of delimiters, XML tags, or unique framing markers to isolate researched data from the agent's core instructions.
- Capability inventory: The skill leverages the agent's ability to read external content and generate send-ready professional communications, providing a pathway for external content to influence output.
- Sanitization: The instructions do not define requirements for sanitizing, escaping, or filtering the content retrieved from external sources before it is processed by the agent.
Audit Metadata