cw-scribe
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user-supplied data, including drafts, notes, and research sources, to direct writing workflows and determine outcomes. This establishes a surface for indirect prompt injection where malicious instructions could be embedded in user-provided content. Ingestion points: User-provided text, notes, and sources are processed at runtime to identify the starting point and active artifacts. Boundary markers: While the skill mentions a 'context-contract.md' for write-safety rules, there are no explicit delimiters or instructions within this skill to ignore embedded commands in user content. Capability inventory: The skill has the ability to write to the file system by creating versioned drafts and can invoke a wide range of specialized sub-skills for brainstorming, structural editing, and publication readiness. Sanitization: There are no explicit instructions for sanitizing, escaping, or validating the external content before it is interpolated into the workflow.
Audit Metadata