content

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the way it handles untrusted external data.
  • Ingestion points: Untrusted data enters the context via web_fetch for URLs, Gmail searches/fetches for emails and newsletters, and extraction from PDFs (SKILL.md Step 1).
  • Boundary markers: The instructions lack delimiters or system-level warnings to distinguish between user instructions and ingested content.
  • Capability inventory: The skill has the capability to read local files, fetch external web content, and access private Gmail data (SKILL.md Step 1).
  • Sanitization: There is no evidence of sanitization or filtering. In fact, Step 3 explicitly commands the agent to "use the user's exact words wherever possible" and "lift sentences directly," which may cause the agent to inadvertently follow malicious instructions embedded in the source content.
  • [DATA_EXFILTRATION]: The skill accesses sensitive data sources including personal emails, newsletters, and local PDF files to generate public-facing social media content. While this is the intended purpose, the combination of private data access and subsequent presentation for public use requires user vigilance to ensure sensitive information is not accidentally included in the drafted posts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 07:43 AM
Security Audit — agent-trust-hub — content