client-satisfaction

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust safety gate by requiring explicit human approval before any client-facing messages are sent, preventing unauthorized or automated external mutations. This policy is stated in the SKILL.md introduction and enforced in Step 6.
  • [SAFE]: The scoring logic is handled by a local Python script (scripts/health-score.py) that uses deterministic arithmetic and standard libraries (argparse, json, sys) without any network access, file system manipulation outside of reading inputs, or dynamic code execution.
  • [SAFE]: Data management is confined to local file paths and a 'second-brain' vault system, with no evidence of sensitive data being exfiltrated to external domains or accessed outside of the user-configured environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes client relationship data which acts as an external input source, creating a potential injection surface. However, the risk is mitigated by deterministic processing and manual review.
  • Ingestion points: Client leading signals such as response latency and sentiment are interpreted from interaction history and ingested into the agent context (SKILL.md Step 1).
  • Boundary markers: The instructions explicitly require the human founder to review all drafted messages before they are sent.
  • Capability inventory: The skill executes a local Python validation script and interacts with a local shell utility (vault.sh) for second-brain operations.
  • Sanitization: The health-score.py script performs strict type checking and range validation on all input factors before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — client-satisfaction