israeli-restaurant-ops
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze and draft responses to customer reviews from delivery platforms, which represents a surface for indirect prompt injection where malicious instructions could be embedded in customer feedback.
- Ingestion points: Customer reviews processed in SKILL.md Step 3 and Step 6.
- Boundary markers: The skill lacks explicit delimiters for review content, though it provides structured Hebrew templates that guide the agent toward safe output formats.
- Capability inventory: The skill primarily utilizes text generation; while references/platform-guides.md mentions browser automation concepts like CDP and cookie storage for portal access, no tools or scripts are provided to execute these actions.
- Sanitization: No specific sanitization or filtering instructions are provided for handling the text of customer reviews before response generation.- [NO_CODE]: The skill consists entirely of Markdown documentation, templates, and metadata. No scripts, binaries, or automated workflows are included in the package.
Audit Metadata