review-brief
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes external visual brief files and source narratives which are untrusted data sources.
- Ingestion points: The skill ingests data from local files matching
*-brief.mdand associated narrative files via theReadtool. - Boundary markers: The instructions do not define clear delimiters or 'ignore' instructions when passing the content of the briefs to the
brief-review-assessoragent. - Capability inventory: The skill has file-write capabilities (modifying briefs and writing JSON artifacts) and the ability to invoke other agents.
- Sanitization: There is no evidence of sanitization, filtering, or validation of the text content retrieved from the files before it is used to drive the revision logic.
Audit Metadata