skills/howells/fiction/critique/Gen Agent Trust Hub

critique

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided manuscript content which may contain hidden instructions (indirect prompt injection). Since the manuscript is treated as data to be read and analyzed, an attacker could include text designed to manipulate the agent's output or actions.
  • Ingestion points: Manuscript files read during the critique process.
  • Boundary markers: None identified. There are no instructions for the agent to use delimiters to separate the manuscript content from its own system instructions.
  • Capability inventory: The skill has the ability to write to files (saving critiques and updating progress tracking).
  • Sanitization: No sanitization or validation of the manuscript content is performed before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 05:14 AM
Security Audit — agent-trust-hub — critique