customer-success-and-retention

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to ingest information from workspace files, which creates a surface for indirect prompt injection if those files contain untrusted content.\n
  • Ingestion points: The skill references reading context from strategy/brand.md, about/me.md, content/ideas.md, content/calendar.md, and legacy marketing context files.\n
  • Boundary markers: The instructions lack explicit delimiters or instructions to treat content from these files as potentially adversarial data.\n
  • Capability inventory: The skill specifies the capability to write generated drafts to the content/ directory based on the ingested data.\n
  • Sanitization: No specific validation or sanitization steps are defined for the data ingested from the workspace context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:06 PM
Security Audit — agent-trust-hub — customer-success-and-retention