alterlab-pra-creative-brief

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8) due to its high level of autonomy and reliance on external data.
  • Ingestion points: The skill explicitly instructs the agent to 'search the web' and 'read existing project files for context' (e.g., marketing plans, research reports, prior briefs).
  • Boundary markers: There are no instructions provided to treat external data as untrusted or to use delimiters to separate user/project data from the agent's core instructions.
  • Capability inventory: The agent has the capability to perform web searches, read local files, and write new files ({project}-creative-brief.md, etc.).
  • Sanitization: No sanitization or validation logic is defined for the content ingested from the web or project files. If an attacker places malicious instructions inside a project file or a web page indexed by the search, the agent may unknowingly execute those instructions while in 'Autonomous' mode.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:44 PM
Security Audit — agent-trust-hub — alterlab-pra-creative-brief