product-review-extractor
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes product reviews from external sources, which constitutes an indirect prompt injection surface. A malicious review could attempt to influence the agent's summary or analysis.
- Ingestion points: Data returned by
sandbase_call_toolfrom various review extraction tools. - Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded commands within the reviews.
- Capability inventory: The skill is limited to synthesis, reporting, and citation. No file-writing, network exfiltration, or shell execution capabilities are mentioned in the provided scripts.
- Sanitization: Absent. There is no explicit requirement for the agent to sanitize or validate the content of the reviews before processing.
Audit Metadata