israeli-restaurant-ops

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze and draft responses to customer reviews from delivery platforms, which represents a surface for indirect prompt injection where malicious instructions could be embedded in customer feedback.
  • Ingestion points: Customer reviews processed in SKILL.md Step 3 and Step 6.
  • Boundary markers: The skill lacks explicit delimiters for review content, though it provides structured Hebrew templates that guide the agent toward safe output formats.
  • Capability inventory: The skill primarily utilizes text generation; while references/platform-guides.md mentions browser automation concepts like CDP and cookie storage for portal access, no tools or scripts are provided to execute these actions.
  • Sanitization: No specific sanitization or filtering instructions are provided for handling the text of customer reviews before response generation.- [NO_CODE]: The skill consists entirely of Markdown documentation, templates, and metadata. No scripts, binaries, or automated workflows are included in the package.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 03:57 PM
Security Audit — agent-trust-hub — israeli-restaurant-ops