posthog-pls-transition-leads

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources such as Salesforce lead details and Vitally account notes which are not under the direct control of the skill author.
  • Ingestion points: Lead matching criteria from Salesforce (SKILL.md Step 1) and account conversations and notes from Vitally (SKILL.md Step 2e).
  • Boundary markers: The skill does not provide instructions to use delimiters or 'ignore' commands when processing this external data.
  • Capability inventory: The skill is capable of performing web searches and fetching arbitrary URLs for validation.
  • Sanitization: There are no specified sanitization or validation routines for data retrieved from external account notes before it is processed.
  • [EXTERNAL_DOWNLOADS]: The skill includes a 'Validate All URLs' step (SKILL.md Step 7) that instructs the agent to fetch every link in the generated outreach draft to verify it resolves. If untrusted data from a lead note or field is interpolated into a URL, the agent will perform a network request to that address.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:47 AM
Security Audit — agent-trust-hub — posthog-pls-transition-leads