commerce-market-research
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection because it is designed to ingest and process external data sources which could contain malicious instructions.
- Ingestion points: The skill reads user-attached files (CSV, Excel, or text exports from keyword tools) and external data from MCP connectors such as Naver DataLab.
- Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat this ingested data as untrusted or to ignore any embedded natural language instructions within the data.
- Capability inventory: The skill utilizes the agent's analytical capabilities to synthesize reports, which requires interpreting the content of external files.
- Sanitization: No validation, escaping, or sanitization logic is implemented for the data processed by the skill.
Audit Metadata