content-creator
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local Python scripts (
scripts/brand_voice_analyzer.py,scripts/seo_optimizer.py) through shell commands as part of its core workflows. - [DATA_EXFILTRATION]: The scripts
brand_voice_analyzer.pyandscripts/seo_optimizer.pyaccept arbitrary file paths as command-line arguments and read the entire content into memory. This creates a potential data exposure surface if the agent is instructed to analyze sensitive system files or credentials (e.g.,.env,.ssh/id_rsa). - [PROMPT_INJECTION]: The skill processes untrusted external content (marketing drafts) through its analysis scripts. The scripts do not sanitize or delimit the input, making them susceptible to indirect prompt injection where malicious instructions hidden in the analyzed text could influence the agent's behavior during the review process.
- Ingestion points:
scripts/brand_voice_analyzer.py(line 144) andscripts/seo_optimizer.py(line 309) read content from files provided as arguments. - Boundary markers: No delimiters or safety instructions are used when reading or processing the content.
- Capability inventory: The scripts perform local file reads but do not have network or file-write capabilities.
- Sanitization: No sanitization is performed on the ingested text to remove or neutralize potential prompt injection patterns.
Audit Metadata