writing-shape

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill utilizes the term 'exploit' (translated in the text as '利用' or 'utilize') to refer to the exploitation phase of a writing process where fixed materials are used to populate a predetermined structure. This is consistent with decision-making terminology and does not represent a security threat.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process untrusted markdown content provided by the user, which presents a potential surface for indirect injection.
  • Ingestion points: The agent reads a user-supplied markdown file ('material pile') to extract content for the article.
  • Boundary markers: The instructions treat the source file as 'read-only' and a 'quarry', though they do not specify technical delimiters to separate content from instructions.
  • Capability inventory: The skill is authorized to read from the disk and append text to files at user-specified paths.
  • Sanitization: While no technical sanitization is described, the workflow involves the model rewriting and transforming snippets to fit a specific prose style, which naturally filters most embedded instructions from being interpreted as commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:25 AM
Security Audit — agent-trust-hub — writing-shape