cw-draft
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data such as outlines, notes, and source materials. This creates a surface for indirect prompt injection if the provided materials contain malicious instructions designed to subvert the agent's behavior.
- Ingestion points: The skill accepts 'outline, notes, source material, or partial prose' as input as described in the name and For Agents sections.
- Boundary markers: The instructions do not specify the use of XML tags, delimiters, or other boundary markers to separate user data from the agent's system instructions.
- Capability inventory: The skill instructions mention creating and managing files within a 'drafts/' directory and reading from a 'references/' directory.
- Sanitization: No explicit sanitization, filtering, or validation of the input content is described.
Audit Metadata