customer-support-ops

Fail

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md direct the agent to execute directory listing commands (ls) on various hidden and local paths, such as ~/.claude/skills/ and ~/.agent/skills/, to perform environment fingerprinting and discover other installed tools.\n- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to suggest and potentially execute npx skills add commands to install additional skills from an unverified source (AbsolutelySkilled). This constitutes a remote code execution risk as it involves fetching and running packages from an external registry without integrity verification.\n- [EXTERNAL_DOWNLOADS]: The skill recommends fetching software components from external npm and GitHub sources associated with an unrecognized vendor, posing a supply chain risk.\n- [PROMPT_INJECTION]: The skill is intended to process customer support tickets containing untrusted text. In references/triage-automation.md, the skill defines keyword-based triage rules that trigger automated actions (tagging, routing, and responses) based on the contents of the ticket's subject or body. Due to the lack of boundary markers or sanitization, this creates an indirect prompt injection surface (Category 8) where malicious instructions inside a ticket could manipulate the agent's logic or downstream workflows.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit — agent-trust-hub — customer-support-ops