retention-engagement
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides links to external templates, worksheets, and benchmark documents hosted on well-known services such as Google Docs, Dropbox, and established industry blogs (e.g., Andrew Chen, Reforge).
- [INDIRECT_PROMPT_INJECTION]: The skill contains instructions for the agent to analyze user-provided data, including onboarding flows, session activity, and CSV files, which presents a surface for indirect prompt injection.
- Ingestion points: Frameworks in
references/artifacts.mdandreferences/guest-insights.mddescribe the processing of user-supplied data files and onboarding telemetry. - Boundary markers: Not present; the skill does not define specific delimiters or instructions to ignore embedded commands in the data being analyzed.
- Capability inventory: The skill functions within the agent's default environment using standard file and analysis tools.
- Sanitization: Not present; there are no explicit validation or escaping mechanisms defined for the external data ingested.
Audit Metadata