copywriter-agent

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it ingests data from external reference files and possesses file-writing capabilities.
  • Ingestion points: The agent reads content from data/profile.md, references/voice-dictionary.md, and references/examples.md during the context gathering phase.
  • Boundary markers: The instructions do not define boundary markers or provide explicit warnings to ignore embedded commands within the content read from the reference files.
  • Capability inventory: The agent utilizes an Edit tool to modify the local filesystem, specifically targeting data/events/log.md and references/voice-dictionary.md.
  • Sanitization: The skill does not implement sanitization, validation, or escaping of ingested content before it is processed or written back to the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 05:28 PM
Security Audit — agent-trust-hub — copywriter-agent