daily-lead-steward
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes external data from CRM records and communication threads, which constitutes a surface for indirect prompt injection.
- Ingestion points: Lead trackers, CRM records, and source threads are ingested as context in
SKILL.mdandSCHEMA-MAP.md. - Boundary markers: No specific delimiters or markers are used in the prompt templates to isolate untrusted data.
- Capability inventory: The skill has the capability to read CRM data, generate digests, and update persistent state via Zapier tools.
- Sanitization: The skill relies on human review and QA steps rather than technical sanitization or input filtering.
- [EXTERNAL_DOWNLOADS]: The skill references the official Zapier SDK for workflow automation and state management.
- [DATA_EXPOSURE]: The skill is designed to handle sensitive enterprise lead information. It mitigates risk by explicitly instructing the agent to keep trackers private and requiring explicit human approval for all source-of-truth updates.
Audit Metadata