content-creator

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local Python scripts (scripts/brand_voice_analyzer.py, scripts/seo_optimizer.py) through shell commands as part of its core workflows.
  • [DATA_EXFILTRATION]: The scripts brand_voice_analyzer.py and scripts/seo_optimizer.py accept arbitrary file paths as command-line arguments and read the entire content into memory. This creates a potential data exposure surface if the agent is instructed to analyze sensitive system files or credentials (e.g., .env, .ssh/id_rsa).
  • [PROMPT_INJECTION]: The skill processes untrusted external content (marketing drafts) through its analysis scripts. The scripts do not sanitize or delimit the input, making them susceptible to indirect prompt injection where malicious instructions hidden in the analyzed text could influence the agent's behavior during the review process.
  • Ingestion points: scripts/brand_voice_analyzer.py (line 144) and scripts/seo_optimizer.py (line 309) read content from files provided as arguments.
  • Boundary markers: No delimiters or safety instructions are used when reading or processing the content.
  • Capability inventory: The scripts perform local file reads but do not have network or file-write capabilities.
  • Sanitization: No sanitization is performed on the ingested text to remove or neutralize potential prompt injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 09:15 AM
Security Audit — agent-trust-hub — content-creator