customer-journey-map

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The instructions contain standard guidance for structuring journey maps. No attempts to override system prompts, bypass safety filters, or use 'DAN' style techniques were detected.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill does not access sensitive system paths (e.g., .ssh, .env) or use network-capable commands like curl or wget. It only processes text provided by the user to generate a journey map report.
  • [OBFUSCATION]: No Base64 encoding, zero-width characters, homoglyphs, or other forms of hidden text were found in the markdown or templates.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: There are no package manifests (package.json, requirements.txt) or commands to install external software. No remote script execution patterns were found.
  • [PRIVILEGE_ESCALATION]: The skill does not use sudo, chmod, or any commands related to modifying system permissions or persistent services.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection via the 'Data sources' input. However, because the skill has no dangerous capabilities (no file writing, no network access, no code execution), this surface does not pose a functional security risk. The skill only performs text interpolation into a structured markdown template.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:03 AM
Security Audit — agent-trust-hub — customer-journey-map