prospect-research-to-cadence
Pass
Audited by Gen Agent Trust Hub on Mar 15, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from web searches, job postings, and third-party enrichment providers to populate email templates. This potential attack surface is mitigated by the 'Stage 3: Approve' step, which uses the AskUserQuestion tool to require manual verification of all generated content before it is used in any downstream automation.\n- [DATA_EXFILTRATION]: Data transfer between the agent context and external services (Apollo, HubSpot, Clay) is explicitly documented as the core functionality of the skill. These interactions target well-known technology providers and are limited to standard prospecting and CRM operations.\n- [SAFE]: No evidence of prompt injection, obfuscation, hardcoded credentials, or unauthorized command execution was found. The skill includes governance filters (Golden Rules) to prevent interaction with existing customers or specific internal accounts, demonstrating a high degree of operational safety.
Audit Metadata