customer-story-writer

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external customer transcripts and notes, which presents a surface for indirect prompt injection.\n
  • Ingestion points: Customer transcripts and interview notes are retrieved via Zapier MCP as described in SKILL.md and SCHEMA-MAP.md.\n
  • Boundary markers: The skill does not employ explicit delimiters or system instructions to distinguish between the drafting task and potential instructions contained within the source material.\n
  • Capability inventory: Using the Zapier SDK and MCP, the skill can perform actions such as updating trackers, routing reviews, and sending approval reminders.\n
  • Sanitization: No specific validation or filtering mechanisms are outlined for the incoming source material.\n- [EXTERNAL_DOWNLOADS]: The setup instructions in SETUP.md involve the zapier-sdk, which is the author's official toolkit for building and managing integrations.\n- [DATA_EXFILTRATION]: The workflow involves retrieving information from CRM systems and content libraries using Zapier's MCP platform to provide context for the customer stories.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:15 PM
Security Audit — agent-trust-hub — customer-story-writer