customer-pulse-check

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFE
Full Analysis
  • External Data Ingestion Surface: The skill is designed to ingest and process information from external sources including HubSpot tickets, PayPal dispute reason codes, and customer review exports (CSV). As with any skill that processes untrusted external content, there is a theoretical surface for indirect prompt injection if the incoming data contains instructions.
  • Evidence of Mitigation: The skill includes explicit 'Approval gates' and instructions to 'Never send response emails automatically,' which ensures a human-in-the-loop remains responsible for all outgoing communication and account actions.
  • Data Privacy Protocols: The instructions include a specific requirement to mask Customer Personally Identifiable Information (PII) by using only first names and last initials in summaries, demonstrating a focus on data privacy best practices.
  • Tool Capability Context: The skill is configured with access to Bash and WebFetch. While these are powerful tools, they are utilized here to facilitate the aggregation of feedback signals and the processing of data files as part of the intended customer synthesis workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 05:33 PM