voice
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from various external channels such as app store reviews, social media, and support tickets, creating an attack surface for indirect prompt injection.
- Ingestion points: The
reference/multi-channel-synthesis.mdfile defines a source inventory that includes public-facing reviews, social media monitoring, and customer support tickets. - Boundary markers: The skill instructions include a "contamination gate" to identify synthetic feedback but do not specify the use of clear delimiters or instructions to ignore commands embedded within the user feedback verbatims.
- Capability inventory: The agent possesses the ability to classify feedback and route actionable insights to other agents, including
Scoutfor bug investigation andSparkfor product feature design. - Sanitization: The skill implements synthetic feedback detection using lexical uniformity and perplexity checks to filter bot responses, but lacks specific sanitization logic to neutralize adversarial prompt injection attempts contained in user text.
Audit Metadata