writing-fragments

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions in SKILL.md define a workflow where user-supplied text is written to a markdown file and subsequently read back into the active agent context. This establishes an attack surface for indirect prompt injection if the fragments stored in the file contain malicious instructions intended to manipulate the agent's behavior during the re-reading phase.
  • Ingestion points: User conversation and the resulting markdown file where text fragments are stored and re-read (SKILL.md).
  • Boundary markers: The skill uses markdown horizontal rules (---) to separate fragments, which serve a structural purpose but do not function as security boundaries to prevent instruction following from within the data.
  • Capability inventory: The skill instructions involve file read and file append operations to manage the writing document.
  • Sanitization: There is no mechanism described for sanitizing, escaping, or validating the content read from the file before it is re-incorporated into the agent's context.
  • [NO_CODE]: This skill consists exclusively of markdown instructions and YAML metadata. It does not include any scripts, compiled binaries, or external package dependencies that could introduce executable code risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:03 AM
Security Audit — agent-trust-hub — writing-fragments