huashu-article-edit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text provided by users in the form of articles, which creates a surface for indirect prompt injection where malicious instructions could be hidden in the article content.
- Ingestion points: The process begins by using a 'Read' tool to ingest the full text of a target article into the agent's context (Step 1).
- Boundary markers: The instructions do not specify the use of XML tags or other delimiters to isolate the article content from the agent's instructions.
- Capability inventory: The skill possesses file read and write capabilities to allow for editing and saving changes.
- Sanitization: While no technical sanitization is mentioned, the skill includes a critical security control by requiring the agent to wait for explicit user confirmation of the modification list before performing any edits (Step 2).
Audit Metadata