gumroad-support-refund-request
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of buyer refund tickets, which provides an attack surface for instructions embedded in user messages.
- Ingestion points: The skill ingest support tickets and buyer messages during the eligibility verification and classification steps described in SKILL.md.
- Boundary markers: The instructions do not define boundary markers (such as XML tags or unique delimiters) to separate the untrusted ticket content from the skill's operational instructions.
- Capability inventory: The agent has the capability to perform production lookups and execute admin-level refunds, including a
--forceparameter, as noted in the execution steps. - Sanitization: No sanitization, filtering, or validation of the incoming ticket content is specified before the agent makes eligibility decisions based on that content.
Audit Metadata