event-feedback

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze free-text feedback from event participants (attendees, speakers, sponsors). While this presents a surface for indirect prompt injection, the skill includes explicit sanitization and safety logic to mitigate risks. It mandates grouping free text into themes with counts rather than raw analysis, requires the redaction of personal names from all findings and quotes, and provides a separate pipeline for handling code-of-conduct allegations. No high-risk capabilities (such as shell execution or network writes) are associated with the processing of this external data.
  • [EXTERNAL_DOWNLOADS]: The documentation references external research and case studies from well-known organizations including WordPress (make.wordpress.org), CNCF (cncf.io), and Major League Hacking (mlh.io). These references are used for evidence-based benchmarking of response rates and satisfaction thresholds. These sources are established technology entities and the references are documented neutrally for informational purposes.
  • [COMMAND_EXECUTION]: No shell commands, subprocess invocations, or script executions were detected in the skill instructions or metadata. The workflow is entirely prompt-based and instructional.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets were found. The skill instructions specifically distinguish between anonymous and identified responses for prize draws, advising organizers on identity management purely for survey administration purposes.
  • [OBFUSCATION]: The skill body and referenced files contain no Base64-encoded executable strings, zero-width characters, or homoglyph attacks. All content is presented in clear-text Markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:13 PM
Security Audit — agent-trust-hub — event-feedback