customer-research
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill does not contain any evidence of hardcoded credentials, malicious persistence mechanisms, or unauthorized network operations. It uses standard markdown formatting and clear instructional logic.
- [SAFE]: References to external services like SparkToro and Reddit are for manual research or well-known information gathering purposes and do not involve remote code execution or automated downloads.
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, including customer transcripts, survey responses, and community posts (Reddit, G2, etc.) in both Mode 1 and Mode 2. It lacks explicit instructions for the agent to use boundary markers or to ignore instructions that might be maliciously embedded within these external sources (Indirect Prompt Injection).
- Ingestion points: Processes raw transcripts, survey results, and forum posts identified in
SKILL.mdandreferences/source-guides.md. - Boundary markers: None provided in the instructions.
- Capability inventory: The skill includes instructions to synthesize data and hand off to other skills (e.g.,
copywriting,page-cro), which could propagate injected instructions. - Sanitization: No sanitization or validation steps are defined for the external data being processed.
Audit Metadata