customer-research
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its core function of processing untrusted external data.
- Ingestion points: The skill ingests data from external public sources such as Reddit comments (reddit/posts/{id}/comments), TikTok comments (tiktok/videos/{id}/comments), and news articles via UnifAPI.
- Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore potential instructions embedded within the ingested social media comments.
- Capability inventory: The skill is primarily designed for data retrieval and report generation; it does not explicitly request file-write or arbitrary code execution capabilities, which limits the potential impact of an injection.
- Sanitization: The instructions do not specify any automated sanitization or filtering of the retrieved content, although they do emphasize verbatim quoting and citation.
Audit Metadata