jtbd

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides workflows for ingesting and analyzing untrusted external content from voice transcripts and customer reviews. This represents a potential vulnerability surface common to data-processing AI agents.
  • Ingestion points: Instructions in SKILL.md direct the agent to read user-provided files such as voice transcripts and review exports (CSV/JSON) into its context for analysis.
  • Boundary markers: The skill does not currently specify the use of delimiters or 'ignore embedded instruction' markers when the agent processes the ingested text.
  • Capability inventory: The skill includes capabilities to write local Markdown and JSON files and to start a local HTTP server on the loopback interface (127.0.0.1) for visualization. These capabilities are used for intended project documentation purposes.
  • Sanitization: Ingested content is processed using heuristic classification scripts (e.g., ingest_transcript.py) which utilize regex and keyword matching, but no sanitization of embedded LLM instructions is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:37 PM