customer-journey-mapper

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from the public web which is then used to generate content and potentially influence agent actions.
  • Ingestion points: External data is retrieved via WebSearch and WebFetch tools as described in the Workflow (Step 2) and Research Protocol sections of SKILL.md and references/examples.md respectively.
  • Boundary markers: The instructions lack explicit boundary markers or XML-style delimiters to separate untrusted web content from internal logic, nor do they include instructions to the model to ignore embedded commands in the researched material.
  • Capability inventory: The skill has access to sensitive tools including Bash, Write, and Edit, which could be abused if the model follows instructions embedded in third-party websites (e.g., customer reviews or competitor pages).
  • Sanitization: There are no mentioned sanitization or filtering steps for the data retrieved through web research before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — customer-journey-mapper