product-review-extractor

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes product reviews from external sources, which constitutes an indirect prompt injection surface. A malicious review could attempt to influence the agent's summary or analysis.
  • Ingestion points: Data returned by sandbase_call_tool from various review extraction tools.
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded commands within the reviews.
  • Capability inventory: The skill is limited to synthesis, reporting, and citation. No file-writing, network exfiltration, or shell execution capabilities are mentioned in the provided scripts.
  • Sanitization: Absent. There is no explicit requirement for the agent to sanitize or validate the content of the reviews before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — product-review-extractor