a1-cold-email
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as recipient dossiers, prospect research, and offer briefs. While this creates a potential surface for indirect prompt injection, the skill includes a 'Source Policy' and 'Cold-Email Spine' that strictly limit the agent to using only verified, supplied facts and acknowledging uncertainty, which serves as a significant mitigation. \n
- Ingestion points: The SKILL.md entry contract and references/source-policy.md define the data inputs (dossiers, research, profiles).\n
- Boundary markers: The instructions include explicit directives in evaluation cases (e.g., 'Must Preserve', 'Forbidden') and a runtime policy that mandates grounding relevance in specific sources.\n
- Capability inventory: The skill is restricted to reading specific local configuration files and generating text. It possesses no capabilities for executing system commands, performing network operations (other than providing a support link), or writing to the file system.\n
- Sanitization: The 'Source Policy' acts as a logical constraint, explicitly forbidding the invention of relationships, praise, or results not present in the input material. \n- [SAFE]: The skill includes a support footer linking to a Telegram channel (https://t.me/a1_marketing_skills). This is a standard support mechanism and uses a well-known messaging service.
Audit Metadata