customer-reply

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional text, communication principles, and message templates. There are no associated scripts, binaries, or executable commands within the provided content.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates intended to process external data (such as customer names, defect reports, and billing issues) into support replies.
  • Ingestion points: Untrusted data enters the context via placeholders in the situational message frameworks in SKILL.md (e.g., [Name], [Current understanding of the behavior]).
  • Boundary markers: The templates do not use specific delimiters or instructions to ignore potential commands embedded in customer input.
  • Capability inventory: The skill has no defined tools, subprocess calls, or network capabilities.
  • Sanitization: There is no mention of sanitizing or escaping customer-provided content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:23 AM
Security Audit — agent-trust-hub — customer-reply