churn-risk-detector

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted external data sources without sufficient isolation.\n- Ingestion points: As specified in Phase 0 and Phase 1 of SKILL.md, the skill ingests data from support ticket exports (CSV), Slack channel histories, and email communication logs.\n- Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings, which could lead the agent to follow instructions maliciously embedded in customer communications.\n- Capability inventory: The agent uses analyzed data to generate 'Root cause hypotheses', 'Save plays', and 'Talk tracks' (Phase 3), creating a path where injected content can influence the agent's reasoning and subsequent interactions.\n- Sanitization: No sanitization or validation mechanisms are described to filter potentially harmful content from the ingested signals before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — churn-risk-detector