find-customer-quotes

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • Indirect Prompt Injection Surface: The skill processes external data (meeting transcripts) which could theoretically contain malicious instructions. However, the risk is handled by the skill's design for verbatim extraction and reporting without execution of the processed content. \n- Ingestion Points: Data enters the agent context via meeting transcripts and call notes fetched from the environment. \n- Boundary Markers: Extracted quotes are clearly delimited using double quotes in the generated output, helping to distinguish between user data and system instructions. \n- Capability Inventory: The skill is designed for analysis and reporting; it does not possess capabilities for file modifications, external network requests, or code execution. \n- Sanitization: A multi-layered verification process filters for high-confidence customer quotes and identifies potential gaps, acting as a functional filter for relevant content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 09:18 AM
Security Audit — agent-trust-hub — find-customer-quotes