product-analytics
Warn
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Deceptive Content and Bloating. The skill folder contains eight massive reference files (such as
architecture-patterns.md,security-best-practices.md, andtesting-strategies.md) that are not mentioned in the mainSKILL.mdreference list. These files consist of approximately 1,350 sections of repetitive technical jargon shuffled to mimic advanced documentation. This technique functions as a form of obfuscation by creating extreme noise, potentially designed to overwhelm security scanners or exhaust the agent's context window to degrade performance. - [PROMPT_INJECTION]: Indirect Prompt Injection Surface. In
SKILL.md, the agent is instructed to ingest untrusted user-supplied data (such as analytics platform names, user journey descriptions, and North Star metrics) into a strictly formatted response. The skill lacks explicit boundary markers or instructions to disregard embedded commands in the input context, providing a surface for attackers to influence the agent's behavior through crafted metadata.
Audit Metadata