pulse

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured templates and best-practice guidance for metrics architecture, including North Star Metrics, KPI trees, and event schemas. No malicious patterns or security risks were identified.
  • [SAFE]: All external URL references target official documentation, industry benchmark reports, and reputable news sources from well-known technology and analytics service providers (e.g., Google, Amplitude, Mixpanel, PostHog, dbt Labs, a16z, Merkle). These references are documented neutrally and serve an informative purpose.
  • [SAFE]: Implementation examples utilize standard, widely-adopted Node.js libraries for analytics tracking (e.g., @amplitude/analytics-browser, posthog-js) and data validation (zod). No suspicious dependencies or remote code execution patterns were found.
  • [SAFE]: The skill incorporates robust privacy guidelines, providing specific implementation patterns for PII removal and compliance with modern privacy standards like GDPR and Google Consent Mode v2.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines clear data ingestion points from other agent skills, such as user feedback (Voice) and conversion goals (Growth). While this creates a theoretical attack surface, the risk is mitigated by explicit instructions for PII filtering and privacy reviews. Evidence:
  • Ingestion points: Defined in SKILL.md under Collaboration Patterns (e.g., VOICE_TO_PULSE, GROWTH_TO_PULSE).
  • Boundary markers: The skill mandates privacy reviews for every tracking point in the Core Contract.
  • Capability inventory: Capabilities include network operations for analytics tracking (reference/platform-integration.md) and local file updates for journaling (.agents/pulse.md).
  • Sanitization: A specific removePII utility function is provided in reference/privacy-consent.md to sanitize event payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:56 AM
Security Audit — agent-trust-hub — pulse