subject-line-lab
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it reads and processes email subject lines and preheaders from external campaign history without clear boundaries or sanitization. \n
- Ingestion points: Data is pulled from external email service providers (Klaviyo, Mailchimp, Rule, and Get a Newsletter) as described in Step 1. \n
- Boundary markers: The instructions lack explicit markers to delimit untrusted data or warnings to ignore instructions embedded in the analyzed strings. \n
- Capability inventory: The skill has access to file system operations (Write, Bash) and vendor-specific tools (mcp__cogny__write_context_node, mcp__cogny__create_finding) for persisting data. \n
- Sanitization: There are no documented steps for sanitizing or validating ingested campaign data before it is used to influence the generation of new content.
Audit Metadata