customer-pain-mining
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external public sources (Reddit, LinkedIn, YouTube, Twitter, and general web search) which constitutes an indirect prompt injection attack surface.
- Ingestion points: Untrusted content is fetched via
mcp__claude_ai_Anysite__executeandmcp__claude_ai_Exa__web_search_exa(SKILL.md). - Boundary markers: The skill does not specify the use of clear delimiters or instructions to ignore embedded commands within the extracted customer verbatim text.
- Capability inventory: The skill has limited capabilities, primarily focused on report generation; it does not request file system access, shell execution, or additional network capabilities beyond the MCP tool invocations.
- Sanitization: There are no explicit steps to sanitize or filter potential instructional content embedded within the customer quotes before they are processed for the final report.
Audit Metadata