blog-brief
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it incorporates content from external websites (via web search) and project files (DISCOURSE.md) into the generated brief without specific sanitization or boundary markers.
- Ingestion points: Web search results (Step 2, 3, 4) and the DISCOURSE.md file (Auto-loaded inputs section).
- Boundary markers: None specified in the instructions.
- Capability inventory: Web search tool access and file writing within the briefs/ directory.
- Sanitization: No specific filtering, escaping, or validation of the ingested external content is mentioned.
- [EXTERNAL_DOWNLOADS]: The skill recommends fetching images and research data from established and well-known services such as Pixabay, Unsplash, and Pexels.
Audit Metadata