customerio-primary-workflow

Pass

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No instructions to override agent behavior or bypass safety filters were detected.
  • [Data Exposure & Exfiltration] (SAFE): The skill uses environment variables for sensitive API keys and does not access or exfiltrate sensitive local files.
  • [Obfuscation] (SAFE): No obfuscated, encoded, or hidden content was found in the instructions or code.
  • [Unverifiable Dependencies & Remote Code Execution] (SAFE): The skill utilizes the official and well-known @customerio/track npm package for its intended functionality.
  • [Indirect Prompt Injection] (SAFE): No risk of indirect prompt injection was identified as the skill provides code templates rather than processing untrusted data within the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 18, 2026, 09:24 PM