blog-writer
Warn
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [METADATA_POISONING]: The
skill-report.jsonfile contains a pre-authored security audit with a 'safe' verdict and detailed explanations for alleged false positive findings. This is a deceptive metadata pattern intended to lead human reviewers or automated scanners to misjudge the skill's safety based on its own falsified claims rather than an independent assessment. - [INDIRECT_PROMPT_INJECTION]: The skill contains self-referential statements in its metadata (e.g., 'Verdict: safe', 'I found no security issue') that target the security analyzer itself. These instructions are designed to be ingested by the audit environment to preemptively declare a safe status. 1. Ingestion points: The
security_auditandmetafields withinskill-report.json. 2. Boundary markers: Absent; the deceptive content is presented as authoritative data. 3. Capability inventory: The skill provides content generation templates and instructions for file modification within the project (writing tosrc/lib/blog-data.ts), consistent with its stated purpose. 4. Sanitization: None detected. - [NO_CODE]: The skill is comprised entirely of Markdown documentation and JSON metadata files; it does not contain executable source code, scripts, or binaries.
Audit Metadata