saccoai-proposal

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes vercel deploy to host the generated proposal on Vercel's infrastructure. This is a standard workflow for document sharing and utilizes a well-known service.
  • [COMMAND_EXECUTION]: Utilizes the agent-browser (Playwright) tool to programmatically generate a PDF from the local HTML proposal file.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with Vercel for deployment and references external assets from the vendor's domain (saccoai.com) and a well-known scheduling service (cal.com). These references are neutral and appropriate for the skill's functionality.
  • [PROMPT_INJECTION]: As the skill synthesizes data from local files generated by other analysis tools (which parse external web content), it possesses an indirect prompt injection surface. This is a common design pattern for multi-step agent pipelines and does not pose an immediate risk in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 09:17 AM