crm-sales-momentum

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No direct prompt injection, system prompt extraction, or safety bypass instructions were detected. The skill follows its defined purpose of analyzing CRM data.- [DATA_EXFILTRATION]: The skill accesses HubSpot CRM data (deals, owners, and company details) and records findings via the mcp__cogny__create_finding tool. This data movement is transparent and aligns with the functionality provided by the vendor, Cogny AI.- [REMOTE_CODE_EXECUTION]: No patterns of remote script execution or unauthorized package installations were found. The skill relies on authorized MCP tools for platform interaction.- [COMMAND_EXECUTION]: The skill utilizes Bash, Read, and Write tools to perform local data analysis and generate reports. These operations are scoped to the skill's analytical requirements and do not involve unauthorized privilege escalation or system persistence.- [PROMPT_INJECTION]: The skill processes external data from HubSpot, which represents a surface for indirect prompt injection. However, it lacks dangerous interpolation patterns and operates within a structured CRM environment, presenting a standard operational risk profile for data-processing agents.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 06:43 AM
Security Audit — agent-trust-hub — crm-sales-momentum