skills/bbengamin/skills/outreach-push/Gen Agent Trust Hub

outreach-push

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions provide commands for installing the paperclipai CLI globally and executing the @bbengamin/paperclip-mcp-server via npx. These tools are central to the ecosystem described and are provided by the skill's author.
  • [EXTERNAL_DOWNLOADS]: The workflow involves downloading software packages from the npm registry. These resources are identified as vendor-owned tools and are necessary for the skill's operation within the Paperclip platform.
  • [COMMAND_EXECUTION]: The skill uses various shell commands via the paperclipai CLI to manage system goals, projects, and issues. It also includes curl commands to perform environment health checks and verify API availability.
  • [PROMPT_INJECTION]: The skill ingests and processes contact data from an external CRM, creating a surface for indirect prompt injection. This risk is mitigated by explicit operational requirements for human-in-the-loop QA gates and strict schema validation before data is transmitted to external services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:26 PM
Security Audit — agent-trust-hub — outreach-push