outreach-profile

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements robust defensive measures to ensure secure local filesystem operations.
  • Path Traversal Prevention: The instructions explicitly require the agent to reject directory traversal and absolute paths, restricting all file operations to designated local and global profile directories (./profiles/ and ~/.intent-outreach/profiles/).
  • Explicit User Consent: All file creation and overwrite operations require explicit user approval via the AskUserQuestion tool, preventing silent modification of the filesystem.
  • Data Minimization and Security: The skill contains explicit instructions to never store sensitive data such as API keys, tokens, or contact records in the profile files.
  • Schema Enforcement: All profile operations are validated against a specific contract (references/profile-contract.md), ensuring the agent processes only structured data and does not misinterpret the intended use of configuration fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 06:26 PM
Security Audit — agent-trust-hub — outreach-profile