09-lead-delivery-and-reporting
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill does not contain instructions designed to bypass safety filters, override system prompts, or disregard instructions. The language used is strictly operational and descriptive of lead delivery workflows.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were identified. The skill explicitly warns about onward disclosure and data minimization requirements for PII, demonstrating a positive security posture regarding data privacy.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download and execution of remote scripts or unverified third-party packages. Integration with external tools like Slack or CRMs is handled through a structured provider selection process based on internal configurations.
- [COMMAND_EXECUTION]: The skill does not utilize shell commands, system calls, or scripts that perform dangerous filesystem or network operations.
- [OBFUSCATION]: No Base64, hex-encoding, zero-width characters, or homoglyph-based obfuscation techniques were found in the metadata or instructional content.
- [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external signals (such as email replies or calendar RSVPs), these are used as status indicators for reporting rather than being interpolated into command execution or system prompts. The risk is minimized by the requirement for human acknowledgment signals.
- [CREDENTIALS_UNSAFE]: No API keys, tokens, or private keys are hardcoded. The skill references external configuration files for provider setup, which aligns with security best practices.
Audit Metadata