reply-manager

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary functionality is to interact with the La Growth Machine platform via its MCP to fetch and send outreach messages. All network-related operations (sending LinkedIn or email messages) are gated by mandatory user approval steps detailed in the workflow.
  • [SAFE]: External dependencies and installation instructions utilize trusted services. The npx command references the official Vercel Labs 'skills' tool, and git clone targets the vendor's own repository. These are documented as standard deployment methods for this ecosystem.
  • [SAFE]: Data processing involves reading prospect replies from LinkedIn and email. While this presents an indirect prompt injection surface (processing untrusted text), the skill implements a strict taxonomy for classification and a 'quality bar' for output generation, which mitigates the risk of following instructions embedded within prospect messages.
  • [SAFE]: No obfuscation, persistence mechanisms, or unauthorized credential access patterns were detected. All URLs and resources originate from the vendor's primary domain (lagrowthmachine.com) or trusted community platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 10:43 AM
Security Audit — agent-trust-hub — reply-manager