customer-research

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill follows best practices for data synthesis and research methodologies.\n- [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety guidelines were found. The skill processes external data (transcripts, surveys, and web content), which creates a surface for indirect prompt injection; however, it lacks dangerous capabilities that would make this an actionable risk.\n
  • Ingestion points: Customer transcripts, survey results, support tickets, and web content from platforms like Reddit, G2, and Hacker News (as described in SKILL.md and references/source-guides.md).\n
  • Boundary markers: Absent.\n
  • Capability inventory: No subprocess calls, exec/eval functions, or file-writing operations are requested or used by the skill.\n
  • Sanitization: Absent.\n- [DATA_EXFILTRATION]: No commands to exfiltrate sensitive data or hardcoded credentials were identified. The reading of local context files like .agents/product-marketing.md is part of the intended functional design for context-aware research.\n- [REMOTE_CODE_EXECUTION]: No remote code execution patterns or unverifiable dependencies were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 05:45 AM
Security Audit — agent-trust-hub — customer-research