shortform-ideation

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a local shell script, scripts/verify.sh, used for structural linting of backlog and experiment files. Analysis confirms the script is a read-only utility using standard tools like find and grep for text parsing. It does not perform network operations, use elevated privileges, or execute dynamic code from ingested files.
  • [SAFE]: The documentation mandates a strong anti-scraping policy for TikTok and Instagram platforms, directing the agent to use manual user input or sanctioned APIs. This proactive security posture reduces legal and technical risks associated with automated harvesting.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill processes external performance data from 02-DOCS/shortform/ and user-provided trend signals. 1. Ingestion points: local markdown files and manual user input. 2. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the data flow. 3. Capability inventory: The skill lacks network tools, dynamic execution functions (eval/exec), or significant file-system manipulation tools. 4. Sanitization: No validation or filtering of ingested data is performed. The risk is assessed as low due to the lack of exploitable capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — shortform-ideation