humanizer
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input and has access to file manipulation tools, which presents a surface for indirect prompt injection attacks.
- Ingestion points: The agent ingests user-supplied text for processing in the
SKILL.mdinstructions. - Boundary markers: There are no specific delimiters (like triple-backticks or unique tags) or instructions to the agent to ignore instructions embedded within the user-provided text.
- Capability inventory: The skill is granted
Read,Write,Edit,Grep, andGlobtools in the frontmatter ofSKILL.md. - Sanitization: The instructions do not include any steps to sanitize or validate input text before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The installation guide references an external code repository.
- Evidence: The
README.mdinstructs users to download the skill usinggit clone https://github.com/blader/humanizer.git. While this is a common practice for installation, it involves downloading content from an external source.
Audit Metadata