churn-prevention

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of markdown-based instructions and reference materials for SaaS retention strategy. No scripts, binaries, or automated command execution patterns were found.
  • [SAFE]: References to external tools such as Stripe, Chargebee, Paddle, PostHog, and Customer.io are for legitimate implementation purposes and target well-known, trusted services.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read local context files (e.g., .agents/product-marketing.md). While this creates an ingestion surface for potentially untrusted data, the skill lack dangerous capabilities like automated file writing or network exfiltration, making this a standard context-gathering behavior.
  • Ingestion points: .agents/product-marketing.md, .claude/product-marketing.md, product-marketing-context.md (referenced in SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: No subprocess calls or file-write scripts found in the skill's files.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:17 AM
Security Audit — agent-trust-hub — churn-prevention