proposal-writer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted user input (solution details, pricing, client info) and process it into structured documents via MCP tools, creating a standard surface for indirect injection.
- Ingestion points: User-supplied opportunity details, solution descriptions, and project requirements as described in the 'How to Use' section of
SKILL.md. - Boundary markers: Absent. The provided templates interpolate user input directly into Markdown and document structures without explicit delimiters or warnings to ignore embedded instructions.
- Capability inventory: The skill is configured to use the
create_docx,fill_docx_template, andcreate_pptxtools from theoffice-mcpserver, allowing it to write to the local filesystem. - Sanitization: Absent. The skill instructions do not specify any validation, filtering, or escaping of user-provided content before it is processed by the file-writing tools.
Audit Metadata