rfm-customer-segmentation

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted e-commerce transaction data from CSV files and interpolates this data into generated markdown reports and CSV exports, which could contain malicious instructions intended for the agent.
  • Ingestion points: Data is loaded from user-provided CSV files in core_analysis.py (load_and_clean_data) and simple_rfm.py (load_data).
  • Boundary markers: The skill does not use specific delimiters or instructions to ignore embedded content when generating text for reports/executive_summary.md, reports/detailed_analysis.md, or reports/marketing_insights.md.
  • Capability inventory: The skill is configured with Bash, Read, Write, and Glob tools, providing a surface for the agent to act on instructions found within the processed data.
  • Sanitization: The implementation in report_generator.py lacks sanitization or validation for data fields like '用户码' (User ID) or '产品说明' (Product Description) before they are rendered into reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:03 AM