audience-segment-builder
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted external data from customer CSVs and GA4 exports, creating a surface for indirect prompt injection.
- Ingestion points: Customer/CRM CSV and GA4 demographics export files defined in the Skill Contract and Data Sources section of SKILL.md.
- Boundary markers: The Instructions section explicitly directs the agent to treat files as untrusted input and to never follow instructions embedded in CSV, GA4, or pasted data.
- Capability inventory: The skill is authorized to write to memory/ad/audience-segment-builder/, memory/hot-cache.md, and memory/open-loops.md, and mentions the potential use of ad-platform APIs for data uploads.
- Sanitization: The instructions strictly forbid echoing raw PII back to the user and require the agent to work with hashed or aggregate descriptions of segments.
Audit Metadata