instantly-core-workflow-b

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.\n
  • Ingestion points: The workflow ingests lead data from CSV files and retrieves reply events from email inboxes in SKILL.md.\n
  • Boundary markers: There are no specified delimiters or 'ignore' instructions provided to the agent when processing this untrusted external text.\n
  • Capability inventory: The skill utilizes high-privilege tools including Bash, Write, and Edit as specified in the frontmatter.\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation for the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 05:46 PM