persona-customer-support

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill involves triaging and processing incoming customer emails using the gws gmail tool. Since it processes untrusted external content, it is susceptible to indirect prompt injection attacks where malicious instructions hidden in an email could attempt to manipulate the agent's logic.
  • Ingestion points: External email content accessed via gws gmail +triage in SKILL.md.
  • Boundary markers: None. The instructions lack delimiters or directives to ignore instructions embedded in the emails.
  • Capability inventory: The agent can read/send emails, update spreadsheets, post to chat spaces, and insert calendar events using the gws binary.
  • Sanitization: No validation or filtering of email content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:27 PM
Security Audit — agent-trust-hub — persona-customer-support