customer-success-audit

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes arbitrary content from the project's codebase (README, package metadata, source files) to generate an audit report.
  • Ingestion points: Local codebase files processed during Phase 1 through Phase 6 (e.g., SKILL.md Step 1.1, 4.1).
  • Boundary markers: The skill does not implement delimiters or explicit instructions to ignore embedded commands in the files it reads.
  • Capability inventory: The agent has the ability to write files to the local disk (docs/customer-success-audit.md and ~/.claude/projects/skill-telemetry.md).
  • Sanitization: No sanitization or validation of the ingested file content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — customer-success-audit