buildbetter-survey-research

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze survey responses, which constitute untrusted data from external sources.
  • Ingestion points: The workflow incorporates the list-survey-responses and get-survey-response tools to retrieve participant data into the agent's context in SKILL.md.
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters or boundary markers (e.g., XML tags or "ignore instructions" wrappers) when the agent processes raw response text.
  • Capability inventory: The skill environment includes tools for external communication and system mutation, such as add-survey-recipients, send-survey-test-email, update-survey (for activation), and configure-survey-intercept.
  • Sanitization: There are no specific instructions regarding the validation or sanitization of response content before it is used for synthesis or follow-up tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 05:47 PM
Security Audit — agent-trust-hub — buildbetter-survey-research