content-factory-operator

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as customer transcripts, research documents, and market signals to generate content. This creates a surface for indirect prompt injection where malicious instructions embedded in source data could influence the agent's output. The skill mitigates this through a structured 'Quality Gate' and 'Review' process that scores content for source integrity and brand alignment before publication.
  • Ingestion points: Reads and atomizes external source material including transcripts, URLs, and research notes.
  • Boundary markers: Missing specific delimiters for data interpolation, but provides instructions for manual review gates.
  • Capability inventory: Utilizes platform content tools (create_post, generate_image) and routes production to specialized peer skills.
  • Sanitization: Employs a multi-dimensional scoring rubric and an 'Approval Packet' system to ensure human oversight before deliverables are finalized.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:44 PM
Security Audit — agent-trust-hub — content-factory-operator