customer-intel

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and synthesize information from potentially untrusted external sources, including customer tickets, email threads, and public web search results. This creates an attack surface where malicious instructions embedded in these external data sources could attempt to influence the agent's behavior.
  • Ingestion points: The skill methodically processes data from tickets, CRM records, email threads, chat logs, and web searches (detailed in Phase 2 and Phase 3 of SKILL.md).
  • Boundary markers: While the skill mandates structured response formats and source attribution, it does not define specific technical delimiters or "ignore instructions" markers for the raw data ingested from these sources.
  • Capability inventory: The skill requires the agent to read internal documentation, access communication logs, and perform external web searches to assemble research summaries.
  • Sanitization: There are no instructions for sanitizing, filtering, or escaping content found within external sources before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:06 PM
Security Audit — agent-trust-hub — customer-intel