zoom-mcp/revenue-accelerator

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [SAFE]: The skill uses official Zoom developer domains and follows standard patterns for MCP server interaction. All external links point to verified Zoom documentation and services.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools to read conversation transcripts and analysis, which introduces a surface for indirect prompt injection from external data.
  • Ingestion points: Tools get_conversation_transcript and get_conversation_analysis in references/tools.md retrieve external text.
  • Boundary markers: Absent; no specific instructions are included to isolate or ignore instructions within the fetched text.
  • Capability inventory: The skill only provides read-access to ZRA data; no write or execution capabilities are present.
  • Sanitization: Absent; the data is passed directly to the agent context.
  • [NO_CODE]: The provided files contain no executable code or script files, consisting solely of markdown documentation and YAML metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:55 PM
Security Audit — agent-trust-hub — zoom-mcp/revenue-accelerator