daily-lead-steward

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external data from CRM records and communication threads, which constitutes a surface for indirect prompt injection.
  • Ingestion points: Lead trackers, CRM records, and source threads are ingested as context in SKILL.md and SCHEMA-MAP.md.
  • Boundary markers: No specific delimiters or markers are used in the prompt templates to isolate untrusted data.
  • Capability inventory: The skill has the capability to read CRM data, generate digests, and update persistent state via Zapier tools.
  • Sanitization: The skill relies on human review and QA steps rather than technical sanitization or input filtering.
  • [EXTERNAL_DOWNLOADS]: The skill references the official Zapier SDK for workflow automation and state management.
  • [DATA_EXPOSURE]: The skill is designed to handle sensitive enterprise lead information. It mitigates risk by explicitly instructing the agent to keep trackers private and requiring explicit human approval for all source-of-truth updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:15 PM
Security Audit — agent-trust-hub — daily-lead-steward