marketplace-pre-member-personalisation

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions to extract and process untrusted data from external acquisition channels, creating a vulnerability surface for injection attacks.
  • Ingestion points: Untrusted data enters the agent's context through URL paths, referrers, and various tracking parameters such as UTM sources and click IDs (GCLID, FBCLID) as described in signal-extract-role-from-url-and-referrer.md and signal-capture-entry-point-metadata.md.
  • Boundary markers: The instructions and code snippets lack the use of delimiters or explicit guidance to the model to disregard instructions that might be embedded in the external metadata.
  • Capability inventory: The logic described in the skill includes performing network requests (e.g., fetching local rates), database writes (updating the profile feature store), and managing session identity.
  • Sanitization: There is no mention or demonstration of sanitizing or validating the extracted metadata before it is used to influence the personalization logic or stored in the session profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — marketplace-pre-member-personalisation