weekly-report

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided descriptions of tasks, blockers, and plans to generate reports. This input surface could theoretically be used for indirect prompt injection if malicious instructions were included in the task descriptions. However, the skill's functionality is limited to formatting text into templates and creating documents using the provided tools, which presents minimal risk. The skill relies on the user to provide the content for the reports.
  • Ingestion points: User input describing accomplishments and blockers (SKILL.md).
  • Boundary markers: Not explicitly defined in instructions, though templates use Markdown headers as structural delimiters.
  • Capability inventory: File creation and template filling via create_docx and fill_docx_template tools (SKILL.md).
  • Sanitization: None observed; the skill processes natural language input directly into templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:46 AM
Security Audit — agent-trust-hub — weekly-report