store-operations
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill guides the agent to process customer inquiries, order notes, and reviews from the Xiaohongshu platform, which are untrusted external inputs.
- Ingestion points: Customer messages and order details ingested from the Xiaohongshu shop management interface (SKILL.md).
- Boundary markers: Absent. The skill provides response templates but does not include instructions to delimit or ignore potentially malicious content within customer inputs.
- Capability inventory: The instructions involve message response, order processing, and tracking management.
- Sanitization: Absent. There are no guidelines for filtering or sanitizing customer-provided text before interpolation into responses.
Audit Metadata