customer-pain-mining

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external public sources (Reddit, LinkedIn, YouTube, Twitter, and general web search) which constitutes an indirect prompt injection attack surface.
  • Ingestion points: Untrusted content is fetched via mcp__claude_ai_Anysite__execute and mcp__claude_ai_Exa__web_search_exa (SKILL.md).
  • Boundary markers: The skill does not specify the use of clear delimiters or instructions to ignore embedded commands within the extracted customer verbatim text.
  • Capability inventory: The skill has limited capabilities, primarily focused on report generation; it does not request file system access, shell execution, or additional network capabilities beyond the MCP tool invocations.
  • Sanitization: There are no explicit steps to sanitize or filter potential instructional content embedded within the customer quotes before they are processed for the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:22 AM
Security Audit — agent-trust-hub — customer-pain-mining