kelly-support
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from customer messages via email, WhatsApp, and WeChat connectors into the
ticketsbase as described inreferences/support-schema.md. This ingestion surface is mitigated by a mandatory human-in-the-loop review process and a programmatic quality gate (support-qa) defined inapp/app/js/support-model.js. The boundary markers consist of explicit status transitions and automated scans for unapproved commitment language. While the skill possesses capabilities to propose sends, refunds, and escalations, these are secured through required human approval and the enforcement of the 'SHIP' verdict before execution markers are recorded by the trusted script.
Audit Metadata