create-text

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted text from a local datalake and Wikipedia, which could contain malicious instructions (indirect prompt injection).
  • Ingestion points: The build_bank.py script reads from /mnt/storage12tb/extractor_corpus/ and the Wikipedia API.
  • Boundary markers: Output in run.sh uses descriptive headers but does not include explicit delimiters to prevent the agent from following instructions embedded in the chunks.
  • Capability inventory: The skill has access to Bash, Read, and Write tools.
  • Sanitization: Content is chunked but not sanitized for potential prompt injection patterns.
  • [EXTERNAL_DOWNLOADS]: The skill downloads content from a well-known service.
  • build_bank.py fetches article content from Wikipedia to populate the wikipedia domain chunks.
  • [COMMAND_EXECUTION]: The run.sh entry point executes Python code snippets.
  • It uses python3 -c to invoke the skill's logic, passing command-line options via the shell environment.
  • [OBFUSCATION]: The skill contains logic to generate text using obfuscation techniques for testing purposes.
  • corrupt.py implements homoglyph substitution and insertion of invisible Unicode characters to simulate OCR and encoding errors.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — create-text