customer-360
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown documentation and architectural guidelines. No executable scripts, binaries, or active configuration files are present in the package.- [SAFE]: The instructions describe legitimate business workflows for reconciling data across common SaaS platforms like HubSpot, Zendesk, and Stripe. No malicious patterns, obfuscation, or unauthorized data access techniques were detected.- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests untrusted external data such as support tickets and email threads, which is a common surface for indirect prompt injection. This risk is inherent to the skill's primary purpose of summarizing customer context. Ingestion points: support tickets and email interactions described in
SKILL.md. Boundary markers: the guidelines do not explicitly define delimiters for external data. Capability inventory: restricted to data summarization, brief generation, and alerting within the agent context. Sanitization: no explicit sanitization of external text is defined.
Audit Metadata