weekly-report
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided descriptions of tasks, blockers, and plans to generate reports. This input surface could theoretically be used for indirect prompt injection if malicious instructions were included in the task descriptions. However, the skill's functionality is limited to formatting text into templates and creating documents using the provided tools, which presents minimal risk. The skill relies on the user to provide the content for the reports.
- Ingestion points: User input describing accomplishments and blockers (SKILL.md).
- Boundary markers: Not explicitly defined in instructions, though templates use Markdown headers as structural delimiters.
- Capability inventory: File creation and template filling via
create_docxandfill_docx_templatetools (SKILL.md). - Sanitization: None observed; the skill processes natural language input directly into templates.
Audit Metadata