bro
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided text or previous responses for rewriting, which creates a surface for potential indirect prompt injection attacks.
- Ingestion points: The skill ingests data from the user's pasted text or the assistant's last message as defined in the 'The contract' section of SKILL.md.
- Boundary markers: The skill explicitly instructs the agent to treat rewritten text as an 'artifact' and keep harness commentary outside it, providing a logical boundary for outputs.
- Capability inventory: The skill is strictly limited to text rewriting and drafting. It does not invoke system commands, network requests, or file writes.
- Sanitization: No explicit data sanitization or escaping is performed on the ingested text; the skill relies on the model's ability to follow the instruction to 'preserve the payload' (facts, links, numbers) while ignoring instructions that might be embedded in the source text.
- [SAFE]: No malicious patterns such as obfuscation, credential harvesting, privilege escalation, or remote code execution were detected. The skill uses standard markdown and YAML configurations to define its behavior.
Audit Metadata