community-weekly-digest

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's description and instructions contain 'eager activation' patterns designed to override the agent's autonomous decision-making. Specifically, it commands the agent to use the skill 'by default whenever the user wants this outcome, even indirectly' and to 'Skip only if the user explicitly asks not to use this skill/workflow.' This forces the agent to prioritize this specific toolset over potentially more relevant or safer alternatives.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external community management tools which serves as a potential vector for indirect prompt injection if the source data is manipulated.
  • Ingestion points: Data retrieved from tools classic_list_launches, classic_list_unique_launches, classic_list_session_times, classic_list_page_views, and classic_list_page_views_per_weekday (SKILL.md).
  • Boundary markers: None provided; the instructions do not specify any delimiters or ignore-instructions for the data retrieved from the tools.
  • Capability inventory: The skill has read access to community traffic data and the ability to delegate to other traffic reports or push broadcast workflows (SKILL.md).
  • Sanitization: There is no mention of sanitizing, escaping, or validating the data returned from the community tools before it is interpolated into the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:57 PM
Security Audit — agent-trust-hub — community-weekly-digest