interview-writer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data such as articles and links to trigger its analysis phase. This introduces a surface for indirect prompt injection if the source material contains adversarial instructions designed to influence the agent.
  • Ingestion points: User-provided links, articles, and draft ideas in Phase 1 (SKILL.md).
  • Boundary markers: The instructions lack explicit boundary markers or directives for the agent to ignore instructions embedded within the processed content.
  • Capability inventory: The skill utilizes file system access to read and write profile information in the ~/.claude/ directory (SKILL.md).
  • Sanitization: No sanitization or input validation logic is described for the content being analyzed.
  • [COMMAND_EXECUTION]: The skill defines a workflow where the agent is expected to update personalization files on the local file system.
  • Evidence: Phase 4 of the workflow (SKILL.md) instructs the agent to automatically update Markdown files located in the ~/.claude/content-profile/ directory based on the interview results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:22 AM