content-research-writer

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and analyze external content, such as drafts and reference materials located in the sources/ directory. This creates a surface for indirect prompt injection where malicious instructions embedded in research papers or drafts could influence the agent's behavior.\n
  • Ingestion points: The agent reads outline.md, research.md, draft-v1.md, and various files within the sources/ directory (e.g., .md, .pdf).\n
  • Boundary markers: The instructions lack explicit requirements for the agent to use delimiters or ignore instructions found within the analyzed content.\n
  • Capability inventory: The skill utilizes file reading capabilities and network access for research purposes.\n
  • Sanitization: There is no mention of sanitizing or validating the content of the documents being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:56 PM
Security Audit — agent-trust-hub — content-research-writer