customer-research
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill is designed to systematically search and synthesize information from a variety of sources, including external web content and internal communications. This creates a potential surface where the agent could process untrusted data containing embedded instructions.
- [Ingestion Points]: Untrusted data may enter the agent's context through web searches, community forums, and third-party documentation (Tier 4), as well as team chat and email (Tier 3), as specified in
SKILL.md. - [Boundary Markers]: The skill utilizes a structured research brief template to separate findings, which helps organize output. However, it does not include explicit directives for the agent to ignore or isolate instructions that might be contained within the source material itself.
- [Capability Inventory]: The agent has the ability to read from multiple tiers of data (CRM, cloud storage, email, web) and can perform follow-up actions like drafting customer responses or updating internal knowledge bases based on the synthesized research.
- [Sanitization]: The instructions do not specify a process for sanitizing or validating the content retrieved from external integrations or partner documentation before it is interpolated into the final research summary.
Audit Metadata