buildbetter-customer-voice

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions define a read-only workflow for interacting with BuildBetter MCP tools. It includes best practices for data privacy, such as minimizing personal data usage and requiring user approval for any data mutations. The tools and resources mentioned are owned by the vendor buildbetter-app.
  • [PROMPT_INJECTION]: The skill processes customer voice data, which represents an indirect prompt injection surface. 1. Ingestion points: Untrusted customer transcripts and feedback are ingested via get-call-transcript and list-extractions tools mentioned in SKILL.md. 2. Boundary markers: There are no specific delimiters defined to wrap external content or instructions to ignore embedded commands. 3. Capability inventory: The skill is limited to read-only MCP operations and lacks capabilities for system command execution, file system modification, or outbound network requests. 4. Sanitization: The skill does not implement explicit sanitization of ingested transcript text.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — buildbetter-customer-voice