postready
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because it is designed to ingest and process untrusted external data (PDFs, URLs, emails, and newsletters) as source material for content generation.
- Ingestion points: The skill ingests untrusted data through the 'content' step (SKILL.md, Step 1) which processes PDFs, URLs, and pasted text.
- Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the ingested data are defined in this orchestrator.
- Capability inventory: The skill utilizes the agent's capabilities to draft content, perform factual searches/verifications, and rewrite text.
- Sanitization: There is no evidence of sanitization or filtering of the input content before it is processed by the underlying language model.
- [COMMAND_EXECUTION]: The skill mentions file paths (e.g.,
~/.claude/skills/content/SKILL.md) for the purpose of locating and orchestrating local sub-skills. This is standard configuration for modular agent environments and does not involve the execution of arbitrary or malicious shell commands.
Audit Metadata