client-satisfaction
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust safety gate by requiring explicit human approval before any client-facing messages are sent, preventing unauthorized or automated external mutations. This policy is stated in the SKILL.md introduction and enforced in Step 6.
- [SAFE]: The scoring logic is handled by a local Python script (
scripts/health-score.py) that uses deterministic arithmetic and standard libraries (argparse, json, sys) without any network access, file system manipulation outside of reading inputs, or dynamic code execution. - [SAFE]: Data management is confined to local file paths and a 'second-brain' vault system, with no evidence of sensitive data being exfiltrated to external domains or accessed outside of the user-configured environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes client relationship data which acts as an external input source, creating a potential injection surface. However, the risk is mitigated by deterministic processing and manual review.
- Ingestion points: Client leading signals such as response latency and sentiment are interpreted from interaction history and ingested into the agent context (SKILL.md Step 1).
- Boundary markers: The instructions explicitly require the human founder to review all drafted messages before they are sent.
- Capability inventory: The skill executes a local Python validation script and interacts with a local shell utility (
vault.sh) for second-brain operations. - Sanitization: The
health-score.pyscript performs strict type checking and range validation on all input factors before processing.
Audit Metadata