surge-retention
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to rungrepcommands for discovering retention-related infrastructure, such as email providers (SendGrid, Postmark) and tracking logic (churn, D7, D30). These operations are restricted to searching local project files. - [DATA_EXPOSURE]: The agent is instructed to gather sensitive business information, including churn rates, survey responses, and support tickets. This data is used solely for diagnosis within the local context, with no evidence of instructions to exfiltrate this information to external endpoints.
- [PROMPT_INJECTION]: The skill adopts a specific persona ('Surge') and enforces strict output formats. It does not contain instructions to bypass safety guardrails or ignore system prompts.
- [INDIRECT_PROMPT_INJECTION]: The skill may process untrusted data from external sources such as user-provided churn surveys or support tickets.
- Ingestion points: Churn survey responses and support tickets referenced in 'Step 1: Gather the Retention Signal'.
- Boundary markers: None identified; external content is not explicitly delimited.
- Capability inventory: Bash command execution, file system writes (Write/Edit), and web fetching (WebFetch).
- Sanitization: No specific sanitization or validation logic is defined for the ingested data.
Audit Metadata