shop-push-targeted
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a 'human-in-the-loop' security pattern, where an explicit user confirmation ('Confirm send?') is required after a draft is generated and before any write operation is performed.
- [SAFE]: Input validation is applied to the notification message, rejecting empty content, placeholders, and enforcing character length constraints (max 255 characters).
- [SAFE]: The skill utilizes specialized tools within the vendor's own namespace (shop_ and cms_) to perform recipient and resource resolution, adhering to the principle of least privilege.
- [SAFE]: Potential indirect prompt injection surfaces are present as the skill processes customer and prospect data from lists; however, these are effectively mitigated by the mandatory preview/draft and confirmation workflow.
- [SAFE]: No patterns of obfuscation, hardcoded credentials, or unauthorized external data exfiltration were detected.
Audit Metadata