create-text
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted text from a local datalake and Wikipedia, which could contain malicious instructions (indirect prompt injection).
- Ingestion points: The
build_bank.pyscript reads from/mnt/storage12tb/extractor_corpus/and the Wikipedia API. - Boundary markers: Output in
run.shuses descriptive headers but does not include explicit delimiters to prevent the agent from following instructions embedded in the chunks. - Capability inventory: The skill has access to
Bash,Read, andWritetools. - Sanitization: Content is chunked but not sanitized for potential prompt injection patterns.
- [EXTERNAL_DOWNLOADS]: The skill downloads content from a well-known service.
build_bank.pyfetches article content from Wikipedia to populate thewikipediadomain chunks.- [COMMAND_EXECUTION]: The
run.shentry point executes Python code snippets. - It uses
python3 -cto invoke the skill's logic, passing command-line options via the shell environment. - [OBFUSCATION]: The skill contains logic to generate text using obfuscation techniques for testing purposes.
corrupt.pyimplements homoglyph substitution and insertion of invisible Unicode characters to simulate OCR and encoding errors.
Audit Metadata