posthog-pls-transition-leads
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources such as Salesforce lead details and Vitally account notes which are not under the direct control of the skill author.
- Ingestion points: Lead matching criteria from Salesforce (SKILL.md Step 1) and account conversations and notes from Vitally (SKILL.md Step 2e).
- Boundary markers: The skill does not provide instructions to use delimiters or 'ignore' commands when processing this external data.
- Capability inventory: The skill is capable of performing web searches and fetching arbitrary URLs for validation.
- Sanitization: There are no specified sanitization or validation routines for data retrieved from external account notes before it is processed.
- [EXTERNAL_DOWNLOADS]: The skill includes a 'Validate All URLs' step (SKILL.md Step 7) that instructs the agent to fetch every link in the generated outreach draft to verify it resolves. If untrusted data from a lead note or field is interpolated into a URL, the agent will perform a network request to that address.
Audit Metadata