inbound-lead-audit-cx-map

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest data from external sources, specifically CRM timelines, routing evidence, and tracker rows as specified in SKILL.md and metadata.yaml. This creates a potential surface for indirect prompt injection; however, the skill significantly mitigates this risk by explicitly instructing the agent to keep lead data private and mandating human approval before any CRM updates or message sending.
  • [EXTERNAL_DOWNLOADS]: The SETUP.md file provides instructions to utilize the Zapier SDK via npx zapier-sdk login. This is a legitimate tool provided by the vendor for managing developer workflows. Additionally, the skill utilizes a Zapier MCP server hosted at https://mcp.zapier.com, which is an official vendor domain.
  • [SAFE]: The workflow design adheres to the principle of least privilege by recommending read-only tests and draft-only work before enabling writes. The instructions in README.md and SKILL.md prioritize human-in-the-loop governance for all sensitive operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:14 PM
Security Audit — agent-trust-hub — inbound-lead-audit-cx-map