churn-risk-detector
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted external data sources without sufficient isolation.\n- Ingestion points: As specified in Phase 0 and Phase 1 of SKILL.md, the skill ingests data from support ticket exports (CSV), Slack channel histories, and email communication logs.\n- Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings, which could lead the agent to follow instructions maliciously embedded in customer communications.\n- Capability inventory: The agent uses analyzed data to generate 'Root cause hypotheses', 'Save plays', and 'Talk tracks' (Phase 3), creating a path where injected content can influence the agent's reasoning and subsequent interactions.\n- Sanitization: No sanitization or validation mechanisms are described to filter potentially harmful content from the ingested signals before processing.
Audit Metadata