write-content

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection during its research phase (Phase 1), as it ingests content from external search engine results pages (SERPs). The agent is instructed to analyze top ranking results to identify formats and gaps. While instructions embedded in these web pages could potentially influence the agent's output, the skill focuses on structural and topical analysis rather than content execution, and the risk is considered low.
  • [SAFE]: The skill implements a mechanism to persist business context (e.g., brand voice, audience) across sessions by saving user preferences to specific local files such as ~/.claude/projects/ or .cursor/rules/. This functionality is transparently documented and the instructions explicitly mandate that the agent must confirm the write location with the user before saving.
  • [SAFE]: The skill's extensive reference library (34 additional files) contains static guidance on content types, technical SEO, and writing methodologies. These files serve as a knowledge base for the agent's reasoning process and contain no executable code, obfuscated payloads, or instructions to bypass system safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 03:40 AM