writing-shape

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill reads from an input markdown file and appends to an output article file. These operations are conducted locally and are essential to the primary purpose of shaping raw material into a finished document. No sensitive file paths or unauthorized exfiltration attempts were identified.
  • [SAFE]: Analysis of the skill's metadata and instructions regarding the term 'exploit' confirms it is used in the context of the 'Explore/Exploit' framework (refining and using fixed material) common in content strategy, rather than referring to a technical security exploit.
  • [SAFE]: The skill represents a surface for Indirect Prompt Injection (Category 8) as it processes untrusted user-provided markdown. However, the risk is mitigated by the highly structured, human-in-the-loop workflow which requires the user to approve every paragraph and format choice. Ingestion point: User-provided markdown file (SKILL.md). Boundary markers: Absent. Capability inventory: Local file read and append. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 10:39 PM
Security Audit — agent-trust-hub — writing-shape