product-help
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is designed to provide product support by querying official documentation. It enforces strict retrieval limits and requires citations from official sources to ensure information accuracy.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from chatcut.io docs. While this represents a potential surface for indirect prompt injection, the risk is mitigated by restricting access to the vendor's own official domains. Ingestion points: https://chatcut.io/docs (SKILL.md). Boundary markers: Absent (delimiters are not explicitly used for the external content). Capability inventory: Native search and page-reading tools are used to ingest documentation. Sanitization: Absent (no explicit validation of external content mentioned).
- [DATA_EXFILTRATION]: All referenced network resources are within the chatcut.io domain, which belongs to the skill's author. No sensitive environment variables or local files are accessed or transmitted.
- [PROMPT_INJECTION]: The instructions include a policy to protect internal implementation details and unpublished content. This is a standard organizational safety boundary and does not constitute a malicious attempt to subvert the agent's behavior or override system safety protocols.
Audit Metadata