follow-up-after-call

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • Data Ingestion and Processing: The skill is designed to interact with sensitive enterprise data sources including CRM records, email threads, and meeting transcripts to generate post-call follow-up packages. This behavior is standard for its intended use and occurs within the platform's tool-based environment.
  • Indirect Prompt Injection Surface: Since the skill processes external content like meeting transcripts, it presents a potential surface for indirect prompt injection. This is mitigated through design instructions that require the agent to place all drafts in block quotes for user verification and strictly prohibit the automated sending of emails or updating of records without explicit user approval.
  • Ingestion points: Transcript data is ingested from various sources identified in the workflow.
  • Boundary markers: The skill uses Markdown block quotes to isolate drafted content.
  • Capability inventory: The workflow can generate notes or automations, but these actions are gated by user requests.
  • Sanitization: Instructions direct the agent to ensure emails are 'customer-safe' and rely on user review as the final guardrail.
  • Automation and Configuration Management: The skill provides functionality to suggest or create follow-up automations. It includes checks for existing configurations in specific local directories and requires explicit user interaction before making any changes, preventing unintended persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 09:18 AM
Security Audit — agent-trust-hub — follow-up-after-call