blog-outline

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it retrieves data from external web sources and incorporates it into the agent's context to generate outlines.\n
  • Ingestion points: External websites fetched during SERP analysis in Step 2.\n
  • Boundary markers: Absent. There are no instructions to the agent to treat external content as data only or to ignore embedded commands.\n
  • Capability inventory: The skill has file-writing capabilities to the outlines/ directory.\n
  • Sanitization: Absent. No sanitization or validation of the fetched content is performed before processing.\n- [COMMAND_EXECUTION]: The skill requires the agent to manage local files and directories, specifically creating the outlines/ folder and saving markdown files, which typically involves shell command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 08:44 AM
Security Audit — agent-trust-hub — blog-outline