customer-pulse

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • Handling of Untrusted External Data: The skill retrieves information from customer-controlled sources such as Gmail threads, Intercom conversations, and HubSpot tickets as described in the workflow in SKILL.md. This creates a surface for indirect prompt injection, where content within these messages could attempt to bias the thematic analysis or suggested actions. The requirement for verbatim quotes in the report provides a level of transparency that allows the user to verify the source of the findings.
  • Access to Sensitive Information: To perform its intended function, the skill accesses sensitive customer communications and financial dispute data from PayPal, HubSpot, and Gmail. While this is necessary for generating the 'Customer Pulse' report, it involves handling potentially sensitive data within the agent's context. The skill is documented as a read-only tool, which minimizes risks related to unintended record modification.
  • Data Boundary Management: The workflow involves interpolating data from several external platforms into a single analysis. The skill does not explicitly detail specific boundary markers or sanitization steps for the ingested content before processing, which is a standard consideration for analytical tasks that aggregate multiple streams of untrusted natural language data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 05:33 PM