signal-correlation-workbench

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process customer feedback, survey responses, and support data, which are untrusted external inputs.
  • Ingestion points: Qualitative feedback, NPS, CSAT, and CRM data are identified as sources in the 'Framework' section of SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific guidance to ignore potential instructions embedded within the feedback data.
  • Capability inventory: The skill mentions templates for SQL and notebook snippets for data merging and analysis, implying capabilities to execute queries or code.
  • Sanitization: No sanitization, validation, or filtering mechanisms are described for the external content before it is processed by the agent.
  • [NO_CODE]: The skill contains only documentation, frameworks, and templates in markdown format without any accompanying scripts or executable code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:49 AM
Security Audit — agent-trust-hub — signal-correlation-workbench