cross-source-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection. It is designed to ingest and process data from external, potentially attacker-controlled sources such as Gong call transcripts, support tickets (Zendesk/Pylon), and community engagement signals (Common Room). An attacker could place malicious instructions within these sources to influence the agent's behavior during analysis.
  • Ingestion points: Data enters the agent context from BigQuery, HubSpot, Pylon, Zendesk, Common Room, Gong, Prometheus, Grafana, Jira, Stripe, and PostHog via the provider-api-request tool.
  • Boundary markers: The instructions do not include boundary markers or specific guidance to the agent to disregard instructions embedded within the retrieved data.
  • Capability inventory: The skill utilizes powerful capabilities including provider-api-request for network interaction, and save-analysis and adhoc-analysis for persisting data and findings.
  • Sanitization: There is no evidence of content sanitization, escaping, or validation performed on the external data before it is processed or saved to intermediate storage.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 04:50 AM
Security Audit — agent-trust-hub — cross-source-analysis