customer-research

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from online communities (Reddit, Hacker News, G2) and customer transcripts. This inherent functionality creates a potential surface for indirect prompt injection if the source data contains malicious instructions.
  • Ingestion points: Processes raw research materials in Mode 1 (SKILL.md) and gathers online intelligence in Mode 2 (references/source-guides.md).
  • Boundary markers: The instructions do not currently include explicit boundary markers or directives for the agent to ignore instructions embedded within the research data.
  • Capability inventory: The skill leverages standard agent capabilities for file reading and web search.
  • Sanitization: There is no explicit sanitization or filtering logic defined for the external content before it is processed for synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 07:35 PM
Security Audit — agent-trust-hub — customer-research