sales-funnelkit

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill documents the FunnelKit Automations REST API which uses an api_key query parameter for authentication. The instructions proactively highlight the security implications of this method (potential leakage in logs or referrers) and advise users to keep calls server-side to mitigate risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes how to handle incoming webhooks, which constitutes an ingestion point for untrusted external data. While this presents an attack surface common to integration tools, the skill provides a security warning to treat the incoming Webhook URL as a secret.
  • [EXTERNAL_DOWNLOADS]: The documentation includes an installation command for a related skill (npx skills add sales-skills/sales). As this resource belongs to the same author ('sales-skills'), it is categorized as a legitimate vendor resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:16 PM
Security Audit — agent-trust-hub — sales-funnelkit