commerce-market-research

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection because it is designed to ingest and process external data sources which could contain malicious instructions.
  • Ingestion points: The skill reads user-attached files (CSV, Excel, or text exports from keyword tools) and external data from MCP connectors such as Naver DataLab.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat this ingested data as untrusted or to ignore any embedded natural language instructions within the data.
  • Capability inventory: The skill utilizes the agent's analytical capabilities to synthesize reports, which requires interpreting the content of external files.
  • Sanitization: No validation, escaping, or sanitization logic is implemented for the data processed by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — commerce-market-research