rfm-customer-segmentation
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted e-commerce transaction data from CSV files and interpolates this data into generated markdown reports and CSV exports, which could contain malicious instructions intended for the agent.
- Ingestion points: Data is loaded from user-provided CSV files in core_analysis.py (load_and_clean_data) and simple_rfm.py (load_data).
- Boundary markers: The skill does not use specific delimiters or instructions to ignore embedded content when generating text for reports/executive_summary.md, reports/detailed_analysis.md, or reports/marketing_insights.md.
- Capability inventory: The skill is configured with Bash, Read, Write, and Glob tools, providing a surface for the agent to act on instructions found within the processed data.
- Sanitization: The implementation in report_generator.py lacks sanitization or validation for data fields like '用户码' (User ID) or '产品说明' (Product Description) before they are rendered into reports.
Audit Metadata