very-long-text-summarization
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process text from external files or URLs provided by the user. If these documents contain hidden or adversarial instructions, they could influence the behavior of the agent during the extraction and synthesis passes. The risk is relevant because the skill's allowed toolset includes capabilities like Bash and file system modification.
- Ingestion points: Documents are read from the
[file-path-or-url]argument specified in SKILL.md. - Boundary markers: The skill utilizes structured YAML templates (extraction_template and synthesis_template) to guide the model's output, which provides some boundary control.
- Capability inventory: The skill frontmatter allows for the use of
Read,Write,Edit,Bash,Grep, andGlobtools. - Sanitization: The three-pass hierarchical synthesis architecture (Haiku to Sonnet to Opus) provides a layer of distillation that may mitigate simple injections, but the skill does not implement explicit validation or sanitization of the input text content.
Audit Metadata