review-analyzer

Pass

Audited by Gen Agent Trust Hub on Jun 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted customer reviews and feeds them into LLM prompts for VOC analysis. It mitigates prompt injection risks by serializing the untrusted content into structured JSON blocks and truncating review bodies to 500 characters, ensuring the analysis focuses on content semantics rather than embedded instructions.
  • [DATA_EXPOSURE]: Implements a telemetry module to monitor tool usage and performance. This module only collects non-sensitive metadata such as tool names, latency, and hashed product identifiers (ASINs), storing them in local logs or a user-configured Redis instance.
  • [EXTERNAL_DOWNLOADS]: The skill provides a feature to analyze reviews from remote CSV/Excel files. It includes security safeguards such as a 100MB file size limit and restricted file extensions to prevent resource exhaustion or the processing of inappropriate content formats.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 4, 2026, 02:36 PM
Security Audit — agent-trust-hub — review-analyzer