chatplace-marketing-sales

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill identifies the sensitive file path ~/.secrets/chatplace/env for storing API credentials. This is a standard and acceptable practice for managing environment variables in a development context.
  • [DYNAMIC_EXECUTION]: The skill includes a Python script that uses subprocess.run to interact with the ChatPlace API via curl. This functionality is restricted to bulk operations for the service's Knowledge Base and targets the official vendor domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface by processing external data from Instagram and voice transcripts. However, it incorporates robust mitigations including manual verification of test scenarios, a draft approval process with the account owner, and text sanitization (grep) to ensure data integrity before publishing the AI agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 08:54 PM
Security Audit — agent-trust-hub — chatplace-marketing-sales