expansion-signal-spotter
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill requires access to sensitive business information, including customer lists containing MRR/ARR, seat usage, and contact LinkedIn URLs (Phase 0). This data is processed to calculate expansion scores and generate internal reports.
- [PROMPT_INJECTION]: The skill processes untrusted content from the public web, such as news articles, job boards, and LinkedIn posts, via search tools. This creates an indirect prompt injection surface where external content could potentially influence the agent's summary or talk-track generation (Phase 1).
- [COMMAND_EXECUTION]: The instructions include a bash command for scheduling the skill's execution using cron. This is a standard method for implementing the requested weekly reporting cadence.
Audit Metadata