mega-campaign-generator

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: Human-in-the-loop governance: The skill's instructions in SKILL.md and README.md explicitly mandate human approval before performing any write operations, sending emails, or posting to social media. This design prevents the agent from being used for autonomous spamming or unauthorized data modification.
  • [EXTERNAL_DOWNLOADS]: Vendor SDK usage: The SETUP.md file references the use of the zapier-sdk via npm. This is an official development tool provided by the vendor (Zapier) for managing integrated workflows and does not represent an unverified dependency risk.
  • [SAFE]: Indirect Prompt Injection mitigation: Although the skill ingests untrusted data from CRM, docs, and chat threads (identifiable in SKILL.md and SCHEMA-MAP.md), it includes specific guardrails instructing the agent not to invent customer proof or data and to clearly label assumptions, which reduces the surface for indirect prompt injection attacks.
  • [SAFE]: No malicious patterns: A thorough audit of the skill's configuration and markdown instructions found no evidence of obfuscated code, hardcoded credentials, unauthorized network exfiltration, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:14 PM
Security Audit — agent-trust-hub — mega-campaign-generator