customer-success-plan
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions and supporting files demonstrate benign intent, providing templates and guidance for professional documentation. No network requests, file system modifications, or hardcoded credentials were found.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data provided by the user (e.g., account details, stakeholder names, and business goals). \n
- Ingestion points: Required Inputs section in SKILL.md.\n
- Boundary markers: Absent; the skill relies on the LLM to interpolate text into the markdown template.\n
- Capability inventory: Limited to text/markdown generation; no shell execution, file writing, or network capabilities.\n
- Sanitization: Absent. \n
- Conclusion: The risk is minimal because the agent lacks the tools or privileges necessary to act on potentially malicious instructions embedded in the input data.
Audit Metadata