revenue-audit
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external Email Service Providers (ESPs), such as campaign subject lines and flow names, which introduces a surface for indirect prompt injection.
- Ingestion points: External ESP data retrieved via MCP tools.
- Boundary markers: Absent; there are no instructions to the agent to treat external strings as untrusted data or use delimiters.
- Capability inventory: The skill has access to Bash, WebFetch, and Write tools.
- Sanitization: No sanitization or validation of the ingested strings is performed before analysis.- [SAFE]: The skill utilizes vendor-specific Model Context Protocol (MCP) tools (mcp__cogny__) and official ESP tools (mcp__klaviyo__, etc.) for its primary functions. This represents normal vendor functionality.- [SAFE]: No hardcoded credentials, malicious obfuscation, or unauthorized network exfiltration patterns were detected. The tool's behavior is consistent with its stated purpose of auditing email marketing revenue.
Audit Metadata