alterlab-pra-creative-brief
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8) due to its high level of autonomy and reliance on external data.
- Ingestion points: The skill explicitly instructs the agent to 'search the web' and 'read existing project files for context' (e.g., marketing plans, research reports, prior briefs).
- Boundary markers: There are no instructions provided to treat external data as untrusted or to use delimiters to separate user/project data from the agent's core instructions.
- Capability inventory: The agent has the capability to perform web searches, read local files, and write new files (
{project}-creative-brief.md, etc.). - Sanitization: No sanitization or validation logic is defined for the content ingested from the web or project files. If an attacker places malicious instructions inside a project file or a web page indexed by the search, the agent may unknowingly execute those instructions while in 'Autonomous' mode.
Audit Metadata