03-lead-nurture-education
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process external data (e.g., from CRM fields or form submissions) to personalize email sequences. This introduces a surface for indirect prompt injection if the source data is manipulated by an external party to include malicious instructions.
- Ingestion points: CRM behavioral fields, form submissions, and content requests.
- Boundary markers: No explicit instruction-data delimiters are provided in this file to isolate lead data from generation instructions.
- Capability inventory: Content generation, campaign strategy mapping, and routing recommendations.
- Sanitization: The skill mandates using 'reliable' CRM fields and 'safe fallbacks' for missing values.
- [NO_CODE]: The skill consists entirely of instructional text in markdown format and does not provide or invoke any executable scripts, binaries, or complex system configurations.
Audit Metadata