stb-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data provided by the user in the form of business pitches, emails, and sales copy for review.
- Ingestion points: The agent accepts user-supplied text content to perform marketing and business reviews (SKILL.md).
- Boundary markers: The instructions do not include boundary markers or delimiters to separate user content from agent instructions, nor do they include warnings to ignore instructions embedded in the user data.
- Capability inventory: The skill does not define any allowed tools, shell scripts, or network capabilities. The agent's output is limited to text-based feedback within the chat interface.
- Sanitization: There is no evidence of input validation, filtering, or sanitization of the content being reviewed.
Audit Metadata