copy-editing
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the processing of untrusted marketing drafts.
- Ingestion points: Reads a "Source draft path or pasted draft" from user input in SKILL.md.
- Boundary markers: None identified. The workflow does not specify delimiters or instructions for the agent to ignore embedded commands within the ingested draft.
- Capability inventory: Performs file-write operations to the local project directory (SKILL.md).
- Sanitization: None identified. Input content is processed directly for editing passes without specific sanitization steps.
Audit Metadata