lead-intelligence

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection (Category 8) due to its core functionality of processing external data.
  • Ingestion points: Untrusted content is ingested from X posts and bios, LinkedIn profiles, and web search results via the Exa API and browser automation.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its own operational instructions and potentially malicious commands embedded in the retrieved lead data.
  • Capability inventory: The agent has write-access capabilities through the X API (DMs and replies) and can interface with Apple Mail to create email drafts, creating a path for injected instructions to result in outbound communication.
  • Sanitization: The instructions do not specify any validation, filtering, or escaping of external content before it is used to generate personalized hooks and message drafts.
  • [COMMAND_EXECUTION]: Specialized agents within the pipeline, such as the enrichment-agent and mutual-mapper, are granted access to the Bash tool. While intended for local data handling, this capability provides a powerful vector for exploitation if the agent's logic is subverted through untrusted input.
  • [EXTERNAL_DOWNLOADS]: The skill routinely connects to external services including Exa, X, and LinkedIn. While these are well-known platforms, the automated fetching of user-generated content from these sources is the primary vector for data-driven attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 12:58 PM
Security Audit — agent-trust-hub — lead-intelligence