follow-up-after-call
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- Human-in-the-Loop Enforcement: The skill is designed with mandatory review gates for every output type, including email drafts, internal recaps, and CRM notes. It explicitly states that no outreach should be sent and no CRM updates should be performed without direct user confirmation, effectively preventing unauthorized actions.
- Data Access and Privacy: While the skill retrieves sensitive information from calendars, transcripts, and CRM systems, it does so within the context of a 'draft-only' workflow. The instructions emphasize that the agent should not 'invent' details and must use placeholders for unknown information, preserving data integrity.
- Input Sanitization Considerations: The skill processes external data such as call transcripts and chat threads, which inherently presents an indirect prompt injection surface. However, this risk is well-managed by the platform's standard guardrails and the skill's specific procedural rules that require all findings to be grounded in verified source evidence.
- Secure Dependency Management: The skill references internal modular components like the sales user context skill rather than external or untrusted scripts, ensuring a secure execution environment within the authorized platform scope.
Audit Metadata