segment-cdp

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The 'Sharp Edges' section contains repetitive placeholder content ('Issue', 'See docs') with arbitrary severity rankings. This deceptive use of metadata fields fails to provide genuine security guidance and could lead an agent or user to misjudge the actual risks associated with the skill's patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes methods for ingesting and processing external tracking data from browser and server-side sources, which introduces an inherent surface for indirect prompt injection.
  • Ingestion points: Browser-side Analytics.js integration and server-side @segment/analytics-node implementations described in SKILL.md.
  • Boundary markers: Absent. The skill does not provide instructions to delimit or specifically ignore potential commands embedded within tracking event properties.
  • Capability inventory: The skill references capabilities for transmitting data to external Segment destinations.
  • Sanitization: Absent. No validation or sanitization logic is suggested for property values within the tracking events, allowing malicious strings to potentially influence agent behavior during data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — segment-cdp