customer-support
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data in the form of customer support tickets, which represents a potential surface for indirect prompt injection attacks.
- Ingestion points: Incoming support ticket text (e.g., email, chat, or voice transcripts) is processed for triage and drafting replies in
SKILL.md. - Boundary markers: The instructions do not define explicit boundary markers or delimiters for the customer's input text.
- Capability inventory: The skill has no active tools or capabilities (e.g., file system access, network requests, or subprocess execution); it only generates text output for human or agent-assisted workflows.
- Sanitization: No sanitization or filtering of input content is specified. The risk is limited to potential manipulation of the agent's triage or tone logic, which is minimal given the lack of executable capabilities.
Audit Metadata