customer-escalation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to ingest and process untrusted data from multiple sources, including customer-provided issue descriptions and data retrieved from external platforms like CRMs and support tools. 1. Ingestion points: The skill takes a user-provided issue description as an argument and references external data sources (support platform, CRM, chat, project tracker) in the 'Gather Context' section of SKILL.md. 2. Capability inventory: The skill generates structured text and suggests downstream actions such as posting to chat channels or updating customer communications as defined in SKILL.md. 3. Boundary markers: There are no explicit instructions to the agent to treat embedded content as untrusted or to ignore instructions contained within the gathered data. 4. Sanitization: The instructions do not specify any validation or sanitization steps for the external content before it is interpolated into the escalation brief.
Audit Metadata