content-factory-operator
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as customer transcripts, research documents, and market signals to generate content. This creates a surface for indirect prompt injection where malicious instructions embedded in source data could influence the agent's output. The skill mitigates this through a structured 'Quality Gate' and 'Review' process that scores content for source integrity and brand alignment before publication.
- Ingestion points: Reads and atomizes external source material including transcripts, URLs, and research notes.
- Boundary markers: Missing specific delimiters for data interpolation, but provides instructions for manual review gates.
- Capability inventory: Utilizes platform content tools (
create_post,generate_image) and routes production to specialized peer skills. - Sanitization: Employs a multi-dimensional scoring rubric and an 'Approval Packet' system to ensure human oversight before deliverables are finalized.
Audit Metadata