customer-research
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from online communities (Reddit, Hacker News, G2) and customer transcripts. This inherent functionality creates a potential surface for indirect prompt injection if the source data contains malicious instructions.
- Ingestion points: Processes raw research materials in Mode 1 (
SKILL.md) and gathers online intelligence in Mode 2 (references/source-guides.md). - Boundary markers: The instructions do not currently include explicit boundary markers or directives for the agent to ignore instructions embedded within the research data.
- Capability inventory: The skill leverages standard agent capabilities for file reading and web search.
- Sanitization: There is no explicit sanitization or filtering logic defined for the external content before it is processed for synthesis.
Audit Metadata