copywriter
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources within the project environment, which creates a potential surface for indirect prompt injection. If an attacker can influence the files being scanned, they could potentially influence the agent's behavior.
- Ingestion points: The skill scans
.agents/memory/, project documentation,CLAUDE.md, and existing marketing copy to discover brand voice and terminology (SKILL.md). - Boundary markers: The instructions lack explicit boundary markers or instructions to ignore potential hidden commands within the ingested project documentation.
- Capability inventory: The skill's primary capability is text generation as defined in metadata.json. It does not explicitly request tool access for network operations or filesystem writes in its frontmatter.
- Sanitization: There is no evidence of sanitization or filtering of the content retrieved from the project documentation before it is processed by the agent.
Audit Metadata