customer-deck-builder

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill is designed to handle sensitive account and customer data. It contains explicit instructions to resolve accounts only from 'approved CRM or account-data sources' and 'pull only the approved fields needed for the deck.'
  • [DATA_EXFILTRATION]: The skill transmits data to Gamma through Zapier MCP to generate presentations. This is the intended primary purpose of the skill and utilizes the author's own verified integration platform.
  • [COMMAND_EXECUTION]: The skill uses Zapier MCP actions for specific tasks (Gamma creation, data reading). No arbitrary shell command execution or risky system-level operations were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes untrusted external data such as 'meeting notes,' 'research docs,' and 'CRM context.' If these sources contain malicious instructions, they could influence the agent's behavior during deck creation. However, the skill provides clear 'Guardrails' and 'Content Guidelines' to mitigate this, including a requirement for human review before sharing outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:14 PM
Security Audit — agent-trust-hub — customer-deck-builder