saccoai-proposal
Pass
Audited by Gen Agent Trust Hub on Mar 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
vercel deployto host the generated proposal on Vercel's infrastructure. This is a standard workflow for document sharing and utilizes a well-known service. - [COMMAND_EXECUTION]: Utilizes the
agent-browser(Playwright) tool to programmatically generate a PDF from the local HTML proposal file. - [EXTERNAL_DOWNLOADS]: The skill interacts with Vercel for deployment and references external assets from the vendor's domain (saccoai.com) and a well-known scheduling service (cal.com). These references are neutral and appropriate for the skill's functionality.
- [PROMPT_INJECTION]: As the skill synthesizes data from local files generated by other analysis tools (which parse external web content), it possesses an indirect prompt injection surface. This is a common design pattern for multi-step agent pipelines and does not pose an immediate risk in this context.
Audit Metadata