store-growth-audit
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from external sources that could contain malicious instructions. \n- Ingestion points: The
mcp__asc-metadata__list_reviewstool is used to fetch user-generated review text and ratings (referenced asEV.reviewsin item P4.2) into the agent's context. \n- Boundary markers: The instructions do not define explicit delimiters or boundary markers to isolate review content, nor do they include warnings for the agent to ignore embedded instructions within that content. \n- Capability inventory: The skill possesses theWritecapability for local file generation (GROWTH.md), filesystem access (Read,Glob,Grep), and the ability to interact with users viaAskUserQuestion. \n- Sanitization: There are no mentioned mechanisms for filtering, sanitizing, or validating the text content of reviews before it is processed by the agent.
Audit Metadata