03-lead-nurture-education

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process external data (e.g., from CRM fields or form submissions) to personalize email sequences. This introduces a surface for indirect prompt injection if the source data is manipulated by an external party to include malicious instructions.
  • Ingestion points: CRM behavioral fields, form submissions, and content requests.
  • Boundary markers: No explicit instruction-data delimiters are provided in this file to isolate lead data from generation instructions.
  • Capability inventory: Content generation, campaign strategy mapping, and routing recommendations.
  • Sanitization: The skill mandates using 'reliable' CRM fields and 'safe fallbacks' for missing values.
  • [NO_CODE]: The skill consists entirely of instructional text in markdown format and does not provide or invoke any executable scripts, binaries, or complex system configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:13 PM
Security Audit — agent-trust-hub — 03-lead-nurture-education