customer-research

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of Markdown and JSON files. There are no scripts (e.g., Python, Node.js) or compiled binaries, which eliminates risks associated with unauthorized code execution within the skill itself.
  • [PROMPT_INJECTION]: The skill defines workflows for processing untrusted data from external sources like Reddit and G2. This creates a surface for indirect prompt injection, though it is a requirement for the skill's primary research purpose.
  • Ingestion points: External sites (Reddit, G2, LinkedIn, YouTube) and user-provided transcripts or surveys.
  • Boundary markers: No specific boundary markers are defined in the instructions to separate external data from agent instructions.
  • Capability inventory: The skill utilizes standard agent capabilities for browsing the web and reading local context files.
  • Sanitization: No sanitization or validation steps for external content are specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 07:08 AM