dig-through-data-brokers
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: No security issues were detected in the skill instructions or referenced files. The content is purely informational and focuses on investigative workflows.
- [NO_CODE]: The skill contains no executable scripts, configuration files for tool execution, or dynamic context commands. It is restricted to markdown documentation.
- [PROMPT_INJECTION]: The skill documents a workflow that involves the agent ingesting and processing data from untrusted external sources (third-party data brokers and public record aggregators).
- Ingestion points: External people-search aggregators (e.g., Spokeo, BeenVerified) and government record portals (e.g., PACER, land registries) as described in the source catalogue.
- Boundary markers: The skill emphasizes manual verification against primary sources but does not define technical delimiters to prevent the agent from following embedded instructions in external data.
- Capability inventory: The methodology references the use of other tools for reverse phone lookups, email analysis, and company research.
- Sanitization: No data sanitization or escaping procedures are described for handling the external content before it is processed by the agent.
Audit Metadata