language
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes external manuscript content to extract and verify phrases, which creates a surface for indirect prompt injection. Malicious instructions within the manuscript could potentially influence the behavior of the primary or reader agents.\n
- Ingestion points: Manuscript chapters and project style guide (craft/tone.md).\n
- Boundary markers: No delimiters are specified to isolate processed text from agent instructions.\n
- Capability inventory: Reading local files and spawning additional agents to process data.\n
- Sanitization: No input validation or content filtering is mentioned.\n- [NO_CODE]: The skill is implemented solely through markdown instructions and does not include any external scripts or binary executables.
Audit Metadata