customer-research

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and analyze untrusted content from external platforms such as Reddit, G2, and YouTube. 1. Ingestion points: SKILL.md (Mode 2) and references/source-guides.md instruct the agent to gather data from online communities and review sites. 2. Boundary markers: The skill lacks explicit instructions to ignore or sanitize embedded instructions within the processed research material. 3. Capability inventory: The skill facilitates reading external web content and local context files (.agents/product-marketing-context.md), though it does not define high-risk write or execution capabilities. 4. Sanitization: No sanitization or validation of the ingested external content is specified. This represents a low-risk surface inherent to the research task.
  • [SAFE]: No other malicious patterns, obfuscation, or unauthorized data access were detected. The skill uses standard context files and references well-known research platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 05:17 AM
Security Audit — agent-trust-hub — customer-research