chatplace-marketing-sales
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill identifies the sensitive file path
~/.secrets/chatplace/envfor storing API credentials. This is a standard and acceptable practice for managing environment variables in a development context. - [DYNAMIC_EXECUTION]: The skill includes a Python script that uses
subprocess.runto interact with the ChatPlace API viacurl. This functionality is restricted to bulk operations for the service's Knowledge Base and targets the official vendor domain. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface by processing external data from Instagram and voice transcripts. However, it incorporates robust mitigations including manual verification of test scenarios, a draft approval process with the account owner, and text sanitization (grep) to ensure data integrity before publishing the AI agent.
Audit Metadata