content-engine
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by instructing the agent to ingest and process external, potentially untrusted data sources.
- Ingestion points: The 'Source-First Workflow' section in SKILL.md directs the agent to identify and process source sets including published articles, transcripts, and internal memos.
- Boundary markers: No boundary markers (e.g., delimiters) or instructions to disregard embedded commands within the source material are present.
- Capability inventory: The skill references 'x-api' for sourcing recent posts and publishing output, which grants the agent the ability to perform write operations on an external platform based on the processed data.
- Sanitization: There are no instructions for sanitizing or validating the content of the source material before it is used to generate drafts.
Audit Metadata