alterlab-pra-copywriter

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFENO_CODECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a senior advertising copywriter persona. Its instructions are creative and instructional, focusing on copywriting frameworks like AIDA and PAS. There are no attempts to bypass safety filters or override core agent behavior.\n- [NO_CODE]: The skill consists of a single markdown file containing natural language instructions and YAML frontmatter. No external scripts, dependencies, or executable binaries are included.\n- [COMMAND_EXECUTION]: The agent's workflow includes using tools to search the web and read/write files in the local project directory. These capabilities are used legitimately to gather context from creative briefs and output formatted copy decks.\n- [PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it is instructed to ingest data from web searches and user-provided project files.\n
  • Ingestion points: Web search results and local project files (e.g., creative briefs) as described in SKILL.md.\n
  • Boundary markers: The instructions do not specify any markers or delimiters to differentiate between data and instructions when reading external content.\n
  • Capability inventory: The skill has tools for web search and file system access (read/write).\n
  • Sanitization: There is no instruction to sanitize or validate content retrieved from external sources before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:45 PM
Security Audit — agent-trust-hub — alterlab-pra-copywriter