customer-escalation
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill functions as a purely instructional guide for organizing information into an escalation brief.
- [NO_CODE]: The skill consists entirely of Markdown instructions and does not include any scripts, package manifests, or executable commands.
- [PROMPT_INJECTION]: The skill is designed to ingest data from external sources such as support tickets, CRM records, and chat logs via platform connectors. While this represents a surface for indirect prompt injection, the skill lacks any dangerous capabilities (e.g., shell access, file writes, or network requests) that could be exploited if an injection occurred.
- Ingestion points: SKILL.md (Workflow Step 2: Gather Context from support platform, CRM, chat, project tracker, and knowledge base connectors)
- Boundary markers: Absent; the skill uses natural language to guide context gathering
- Capability inventory: No tools, scripts, or subprocess capabilities are defined or requested in this skill
- Sanitization: No explicit sanitization or filtering of connector data is performed
Audit Metadata