email-campaign

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the tdx CLI (a vendor-provided tool) to execute workflows and manage segments. Specifically, it uses tdx wf run to push generated HTML content to the Treasure Engage service. It also employs standard shell commands like cat and cp for file management in temporary directories.
  • [EXTERNAL_DOWNLOADS]: The skill references image assets from well-known, trusted services such as Unsplash and Pexels. These are used strictly for email content and do not involve executable code or sensitive data retrieval.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill processes customer profile data (e.g., first name, loyalty points) via Liquid merge tags. This data is handled within the context of the Treasure Data platform and is intended for personalization of the generated emails. No evidence of unauthorized data transmission to third-party domains was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 06:54 AM
Security Audit — agent-trust-hub — email-campaign