customer-reply
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional text, communication principles, and message templates. There are no associated scripts, binaries, or executable commands within the provided content.
- [INDIRECT_PROMPT_INJECTION]: The skill provides templates intended to process external data (such as customer names, defect reports, and billing issues) into support replies.
- Ingestion points: Untrusted data enters the context via placeholders in the situational message frameworks in
SKILL.md(e.g.,[Name],[Current understanding of the behavior]). - Boundary markers: The templates do not use specific delimiters or instructions to ignore potential commands embedded in customer input.
- Capability inventory: The skill has no defined tools, subprocess calls, or network capabilities.
- Sanitization: There is no mention of sanitizing or escaping customer-provided content before it is processed by the model.
Audit Metadata