mcp-urgent-caller-triage

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates data movement between sensitive sources (phone transcripts, legal records) and delivery channels (Slack, email) using Zapier MCP. It enforces a strict human-in-the-loop policy for all critical actions, such as contacting clients or updating legal records, which prevents autonomous or unintended operations.- [SAFE]: Privacy best practices are integrated into the workflow instructions, requiring the agent to mask caller identifiers and provide neutral reasons for urgency in shared summaries. This minimizes the risk of sensitive data exposure in potentially less-secure communication channels.- [SAFE]: While the skill processes untrusted user input (call transcripts), representing an indirect prompt injection surface, it mitigates risk by limiting the agent's capabilities to read-only summaries and drafting language that requires explicit human approval before execution.\n
  • Ingestion points: Call transcripts and metadata pulled via Zapier MCP (referenced in SKILL.md and ONBOARDING-PROMPT.md).\n
  • Boundary markers: No explicit delimiters for transcript content are specified in the prompts.\n
  • Capability inventory: Write access to Slack, email, and Google Sheets; Read access to legal systems like Clio (all via Zapier MCP/SDK).\n
  • Sanitization: Instructions mandate masking identifiers and using neutral summaries, providing output-level sanitization for sensitive data.- [SAFE]: All external references, including links to documentation and the origin story, point to the vendor's official domain (zapier.com), which is a trusted source.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:15 PM
Security Audit — agent-trust-hub — mcp-urgent-caller-triage