ugc-brief

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data which represents a potential surface for indirect prompt injection attacks.
  • Ingestion points: The inputs product_description, target_audience, and key_talking_points in SKILL.md are directly incorporated into the generation process.
  • Boundary markers: Absent. The skill does not use specific delimiters or instructions to the model to ignore potential commands embedded in the user inputs.
  • Capability inventory: The skill is limited to text generation. No file system writes, network requests, or shell command executions are present in the provided file.
  • Sanitization: No sanitization or validation of the user-provided input strings is performed.
  • [DATA_EXFILTRATION]: The skill contains a hardcoded link to an external domain for attribution.
  • Evidence: https://copyaccelerator.com/join in SKILL.md.
  • Context: This is a legitimate marketing link for the RMBC framework author and does not involve the transmission of sensitive data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 04:37 PM
Security Audit — agent-trust-hub — ugc-brief