customer-research

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, including interview transcripts, survey results, and public online forums. This constitutes an attack surface for indirect prompt injection if the source content contains malicious instructions intended to manipulate the agent's output or behavior.
  • Ingestion points: Raw research assets (transcripts, support tickets) and content from digital watering holes like Reddit, G2, and LinkedIn (SKILL.md, references/source-guides.md).
  • Boundary markers: The skill employs a structured extraction framework (JTBD, pains, triggers) and confidence labeling which helps constrain the agent's focus, though it lacks explicit instructions to ignore commands embedded in the data.
  • Capability inventory: The skill is designed for analysis, synthesis, and persona creation; it does not request or demonstrate access to sensitive system tools, shell execution, or unauthorized network operations.
  • Sanitization: There are no documented steps for sanitizing or filtering external text before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:57 PM
Security Audit — agent-trust-hub — customer-research