ghostwriter
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is composed entirely of instructional markdown and checklists. It does not include scripts, binary files, or commands that interact with the host system.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external content such as transcripts and research notes, which is a potential ingestion surface for indirect prompt injection. However, the skill does not request or use any tools or system capabilities, which effectively eliminates the impact of such an attack. 1. Ingestion points: Source material, research, and interviews described in the workflow (SKILL.md). 2. Boundary markers: The skill does not define specific delimiters for separating untrusted source material from instructions. 3. Capability inventory: No high-risk tools, network access, or file-writing capabilities are requested or used. 4. Sanitization: The skill provides instructions for manual extraction and conversion but does not include automated sanitization or filtering logic.
Audit Metadata