customer-research
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process information from untrusted external sources. An attacker could place malicious instructions within a product review, forum post, or comment that the agent might follow if not properly isolated.
- Ingestion points:
SKILL.mdandreferences/source-guides.mdinstruct the agent to mine data from Reddit, G2, LinkedIn, YouTube, and various online communities. - Boundary markers: The skill lacks explicit instructions or delimiters to help the agent distinguish between research data and executable commands found within the external content.
- Capability inventory: The skill is intended for agents with web browsing and file system access to collect and analyze research assets.
- Sanitization: There are no directives to sanitize or escape the content retrieved from external sources before it is processed by the agent.
Audit Metadata