content
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external content which may contain malicious instructions that could influence the agent's behavior.
- Ingestion points: The skill accepts external drafts and source data in
references/humanize.md(Intake),references/blog.md(Intake), andreferences/audit.md(published content). - Boundary markers: There are no specific instructions to use delimiters or explicit "ignore" instructions within the ingested text to prevent the agent from following embedded malicious commands.
- Capability inventory: The skill is granted access to powerful tools including
bash,run_command,write_to_file, andreplace_file_contentacross all modes in theSKILL.mdandagents/openai.yamlconfigurations. - Sanitization: No explicit sanitization or validation of the input draft content is described before the agent processes and acts upon the text.
Audit Metadata