revenue-audit

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external Email Service Providers (ESPs), such as campaign subject lines and flow names, which introduces a surface for indirect prompt injection.
  • Ingestion points: External ESP data retrieved via MCP tools.
  • Boundary markers: Absent; there are no instructions to the agent to treat external strings as untrusted data or use delimiters.
  • Capability inventory: The skill has access to Bash, WebFetch, and Write tools.
  • Sanitization: No sanitization or validation of the ingested strings is performed before analysis.- [SAFE]: The skill utilizes vendor-specific Model Context Protocol (MCP) tools (mcp__cogny__) and official ESP tools (mcp__klaviyo__, etc.) for its primary functions. This represents normal vendor functionality.- [SAFE]: No hardcoded credentials, malicious obfuscation, or unauthorized network exfiltration patterns were detected. The tool's behavior is consistent with its stated purpose of auditing email marketing revenue.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 06:43 AM
Security Audit — agent-trust-hub — revenue-audit