content-research-writer
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and analyze external content, such as drafts and reference materials located in the
sources/directory. This creates a surface for indirect prompt injection where malicious instructions embedded in research papers or drafts could influence the agent's behavior.\n - Ingestion points: The agent reads
outline.md,research.md,draft-v1.md, and various files within thesources/directory (e.g.,.md,.pdf).\n - Boundary markers: The instructions lack explicit requirements for the agent to use delimiters or ignore instructions found within the analyzed content.\n
- Capability inventory: The skill utilizes file reading capabilities and network access for research purposes.\n
- Sanitization: There is no mention of sanitizing or validating the content of the documents being processed.
Audit Metadata