blog-outline
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it retrieves data from external web sources and incorporates it into the agent's context to generate outlines.\n
- Ingestion points: External websites fetched during SERP analysis in Step 2.\n
- Boundary markers: Absent. There are no instructions to the agent to treat external content as data only or to ignore embedded commands.\n
- Capability inventory: The skill has file-writing capabilities to the
outlines/directory.\n - Sanitization: Absent. No sanitization or validation of the fetched content is performed before processing.\n- [COMMAND_EXECUTION]: The skill requires the agent to manage local files and directories, specifically creating the
outlines/folder and saving markdown files, which typically involves shell command execution.
Audit Metadata