postready

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because it is designed to ingest and process untrusted external data (PDFs, URLs, emails, and newsletters) as source material for content generation.
  • Ingestion points: The skill ingests untrusted data through the 'content' step (SKILL.md, Step 1) which processes PDFs, URLs, and pasted text.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the ingested data are defined in this orchestrator.
  • Capability inventory: The skill utilizes the agent's capabilities to draft content, perform factual searches/verifications, and rewrite text.
  • Sanitization: There is no evidence of sanitization or filtering of the input content before it is processed by the underlying language model.
  • [COMMAND_EXECUTION]: The skill mentions file paths (e.g., ~/.claude/skills/content/SKILL.md) for the purpose of locating and orchestrating local sub-skills. This is standard configuration for modular agent environments and does not involve the execution of arbitrary or malicious shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 07:43 AM
Security Audit — agent-trust-hub — postready