lead-research-assistant

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions (Step 1) prompt the agent to analyze the user's local codebase to understand the product. This context is subsequently used to perform external searches (Step 3). This creates a potential for sensitive project details or proprietary logic to be included in search queries sent to external search providers or used as context for third-party tools.- [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection because it processes untrusted data from the web.
  • Ingestion points: The agent identifies leads by reading external sources such as company websites, job postings, and news articles (SKILL.md, Step 3).
  • Boundary markers: There are no instructions providing delimiters or warnings to ignore commands or instructions embedded within the external content retrieved from the web.
  • Capability inventory: The agent performs local file reading for codebase analysis (SKILL.md, Step 1) and network reading for lead research (SKILL.md, Step 3).
  • Sanitization: No sanitization or validation logic is specified for the data ingested from external research sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:21 PM
Security Audit — agent-trust-hub — lead-research-assistant