store-operations

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill guides the agent to process customer inquiries, order notes, and reviews from the Xiaohongshu platform, which are untrusted external inputs.
  • Ingestion points: Customer messages and order details ingested from the Xiaohongshu shop management interface (SKILL.md).
  • Boundary markers: Absent. The skill provides response templates but does not include instructions to delimit or ignore potentially malicious content within customer inputs.
  • Capability inventory: The instructions involve message response, order processing, and tracking management.
  • Sanitization: Absent. There are no guidelines for filtering or sanitizing customer-provided text before interpolation into responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:45 PM
Security Audit — agent-trust-hub — store-operations