skills/vapiai/skills/create-campaign/Gen Agent Trust Hub

create-campaign

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external contact data from CSV files and API responses, which constitutes an indirect prompt injection surface. This is addressed through robust operational safety rules.
  • Ingestion points: User-supplied customers arrays and CSV contact lists defined in SKILL.md and references/api-reference.md.
  • Boundary markers: The skill includes specific instructions to redact sensitive PII and provide only counts or redacted samples during confirmation steps.
  • Capability inventory: The agent can perform network operations via curl to manage campaigns and calls.
  • Sanitization: The instructions require the agent to verify all live payloads against official schemas and explicitly check consent requirements.
  • [COMMAND_EXECUTION]: The skill uses curl to interact with the Vapi REST API. These operations are directed at the vendor's official domain (api.vapi.ai) and are appropriate for the skill's defined purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:03 AM
Security Audit — agent-trust-hub — create-campaign