customer-success-manager

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of deterministic Python scripts that calculate health scores, churn risk, and expansion opportunities based on local JSON data provided by the user. All scripts use only the Python standard library (argparse, json, sys, datetime) and do not perform any network operations, external downloads, or system modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted customer data from JSON files which are then included in reports intended for the agent to review. While this creates a surface where the agent could be influenced by malicious strings in the input data (e.g., in customer names or sentiment fields), the scripts lack any dangerous capabilities such as shell execution or network access to exploit this surface. Evidence: 1. Ingestion points: JSON input file in scripts/health_score_calculator.py, scripts/churn_risk_analyzer.py, and scripts/expansion_opportunity_scorer.py. 2. Boundary markers: Absent. 3. Capability inventory: None. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:43 PM
Security Audit — agent-trust-hub — customer-success-manager