review-responder

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow for ingesting and processing customer reviews from external sources, which creates a surface for indirect prompt injection. \n- Ingestion points: Review data is collected from platforms such as Google Business Profile, Yelp, TripAdvisor, and Facebook. \n- Boundary markers: The instructions do not provide boundary markers or specific directives for the agent to ignore instructions potentially hidden within the customer reviews. \n- Capability inventory: The agent uses the ingested content to draft public responses, generate sentiment analysis reports, and flag issues for internal review. \n- Sanitization: The workflow does not include any verification or sanitization of the review text before the agent interacts with it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 07:28 PM
Security Audit — agent-trust-hub — review-responder