customer-intel
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill package is comprised solely of a markdown file containing a research framework and metadata. It does not include any Python or Node.js scripts, executables, or environment configurations that could be used for malicious purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill describes procedures for the agent to ingest data from untrusted external sources, including community forums and public web content (SKILL.md). While this represents a potential surface for indirect prompt injection, the skill proactively mitigates this risk through a mandated 'Confidence Rating System' and strict attribution requirements. Furthermore, because the skill lacks code-execution capabilities, the risk of technical exploitation via injection is negligible.
Audit Metadata