content-creator

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of markdown templates and Python scripts that perform local text processing. No external network requests, hardcoded credentials, or obfuscated code were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it is designed to process untrusted text files for SEO and brand voice analysis.
  • Ingestion points: Untrusted text data is ingested through the brand_voice_analyzer.py and seo_optimizer.py scripts via the existing_content.txt and blog_post.md files.
  • Boundary markers: Absent; the scripts read and process the full content of the input files provided as command-line arguments.
  • Capability inventory: The skill uses standard file reading and regex-based analysis. No subprocess spawning or dynamic code evaluation (eval/exec) is present in the provided scripts.
  • Sanitization: No specific sanitization or escaping of the input text is performed before processing, though the scripts only output statistical analysis and recommendations back to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:02 PM
Security Audit — agent-trust-hub — content-creator