plagiarism-checker

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from the web, which creates a potential surface for indirect prompt injection.
  • Ingestion points: Content is retrieved from external websites using WebFetch and from lyric files via the Read tool or MCP functions.
  • Boundary markers: The instructions do not specify the use of delimiters or specific directives to prevent the agent from following instructions that might be present in the fetched lyrics or web pages.
  • Capability inventory: The skill has access to WebSearch, WebFetch, Read, Glob, Grep, and the bitwize-music-mcp toolset.
  • Sanitization: No sanitization or validation of the fetched external text is described before it is analyzed by the model.
  • [SAFE]: The skill's logic is consistent with its stated purpose of plagiarism detection. All identified tools and MCP extensions (bitwize-music-mcp) are associated with the vendor bitwize-music-studio. No evidence of credential harvesting, malicious persistence, or unauthorized data exfiltration was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 01:14 PM