lead-research-assistant
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface as it is designed to analyze external data and repository contents.
- Ingestion points: The skill ingests untrusted data from local codebase repositories and external company research sources (such as job postings and news) when executing lead discovery.
- Boundary markers: Absent; there are no boundary markers or instructions telling the model to disregard malicious prompts embedded within the repository files or external search results.
- Capability inventory: None; the skill does not invoke execution tools, write files, or initiate network connections directly through its instructions.
- Sanitization: Absent; external and codebase data are processed directly for summarizing and scoring without escaping or validation mechanisms.
Audit Metadata