copywriter-agent
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it ingests data from external reference files and possesses file-writing capabilities.
- Ingestion points: The agent reads content from data/profile.md, references/voice-dictionary.md, and references/examples.md during the context gathering phase.
- Boundary markers: The instructions do not define boundary markers or provide explicit warnings to ignore embedded commands within the content read from the reference files.
- Capability inventory: The agent utilizes an Edit tool to modify the local filesystem, specifically targeting data/events/log.md and references/voice-dictionary.md.
- Sanitization: The skill does not implement sanitization, validation, or escaping of ingested content before it is processed or written back to the filesystem.
Audit Metadata