plagiarism-checker
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from the web, which creates a potential surface for indirect prompt injection.
- Ingestion points: Content is retrieved from external websites using
WebFetchand from lyric files via theReadtool or MCP functions. - Boundary markers: The instructions do not specify the use of delimiters or specific directives to prevent the agent from following instructions that might be present in the fetched lyrics or web pages.
- Capability inventory: The skill has access to
WebSearch,WebFetch,Read,Glob,Grep, and thebitwize-music-mcptoolset. - Sanitization: No sanitization or validation of the fetched external text is described before it is analyzed by the model.
- [SAFE]: The skill's logic is consistent with its stated purpose of plagiarism detection. All identified tools and MCP extensions (bitwize-music-mcp) are associated with the vendor bitwize-music-studio. No evidence of credential harvesting, malicious persistence, or unauthorized data exfiltration was found.
Audit Metadata