retention-engagement

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides links to external templates, worksheets, and benchmark documents hosted on well-known services such as Google Docs, Dropbox, and established industry blogs (e.g., Andrew Chen, Reforge).
  • [INDIRECT_PROMPT_INJECTION]: The skill contains instructions for the agent to analyze user-provided data, including onboarding flows, session activity, and CSV files, which presents a surface for indirect prompt injection.
  • Ingestion points: Frameworks in references/artifacts.md and references/guest-insights.md describe the processing of user-supplied data files and onboarding telemetry.
  • Boundary markers: Not present; the skill does not define specific delimiters or instructions to ignore embedded commands in the data being analyzed.
  • Capability inventory: The skill functions within the agent's default environment using standard file and analysis tools.
  • Sanitization: Not present; there are no explicit validation or escaping mechanisms defined for the external data ingested.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:49 PM
Security Audit — agent-trust-hub — retention-engagement