customer-support
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implementation follows standard patterns for building customer support tools and contains no malicious code or instructions.- [COMMAND_EXECUTION]: Database operations utilize parameter binding with psycopg2 to protect against SQL injection, which is a security best practice.- [CREDENTIALS_UNSAFE]: The code correctly uses environment variables (SUPABASE_DB_URL) to store database connection strings rather than hardcoding secrets.- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing customer input. 1. Ingestion points: User query enters via SupportState in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Database read/write (psycopg2) and response generation (OpenAI). 4. Sanitization: Uses parameterized SQL queries. The risk is mitigated by intent classification logic and human-in-the-loop escalation thresholds.
Audit Metadata