skills/happy-technologies-llc/happy-platform-skills/hrsd-chat-reply-recommendation/Gen Agent Trust Hub
hrsd-chat-reply-recommendation
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it incorporates untrusted external data into its response generation process.
- Ingestion points: Untrusted data enters the context via chat messages from
sys_cs_messageand article content fromkb_knowledge. - Boundary markers: There are no defined delimiters or instructions to ignore embedded commands within the prompt logic described in Step 7.
- Capability inventory: The skill can perform write operations to ServiceNow via
SN-Add-Work-Notesand has access to theBashtool. - Sanitization: No data validation, escaping, or sanitization steps are documented for the retrieved text before it is used to generate recommendations.
Audit Metadata