customer-win-back-sequencer
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security violations were detected in the analyzed files. The skill's operations are transparent and align with its described business functionality.
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it processes external CSV data provided by the user. However, the instructions are well-structured for data extraction and template generation rather than command execution.
- Ingestion points: Churned Account Data (CSV/sheet) defined in SKILL.md Phase 0.
- Boundary markers: None explicitly defined; data is interpolated directly into research queries and email templates.
- Capability inventory: Includes web search, webpage fetching, external tool calls (linkedin-profile-post-scraper, review-scraper), and campaign setup (setup-outreach-campaign).
- Sanitization: No explicit validation or escaping of input data is mentioned.
- [DATA_EXFILTRATION]: The skill processes customer PII and financial metrics (MRR). This information is used legitimately to perform targeted research and configure outreach campaigns on well-known services like Smartlead, which is consistent with the skill's purpose.
Audit Metadata