personize-code-pipelines
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from multiple sources (emails, CRM records, web research) and interpolates it into AI prompts. This creates a surface for indirect prompt injection.\n
- Ingestion points: Inbound email bodies in
pipelines/conversational/email-reply-handler.ts, CRM properties inpipelines/crm/hubspot-lead-review.ts, and web search results inpipelines/signals/account-monitor.ts.\n - Boundary markers: Prompts use markdown headers like
## Contact Contextand## Organizational Guidelinesto delimit data from instructions.\n - Capability inventory: The skill can send emails (via Gmail/SendGrid), post to Slack channels, and update CRM records in HubSpot and Salesforce.\n
- Sanitization: Employs
zodfor payload validation andstripQuotedReplyinscaffold/lib/gmail.tsfor cleaning email content.
Audit Metadata