content-engine

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by instructing the agent to ingest and process external, potentially untrusted data sources.
  • Ingestion points: The 'Source-First Workflow' section in SKILL.md directs the agent to identify and process source sets including published articles, transcripts, and internal memos.
  • Boundary markers: No boundary markers (e.g., delimiters) or instructions to disregard embedded commands within the source material are present.
  • Capability inventory: The skill references 'x-api' for sourcing recent posts and publishing output, which grants the agent the ability to perform write operations on an external platform based on the processed data.
  • Sanitization: There are no instructions for sanitizing or validating the content of the source material before it is used to generate drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:00 AM
Security Audit — agent-trust-hub — content-engine