copy-editor
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and refine arbitrary prose, creating a surface for indirect prompt injection if the input text contains malicious instructions aimed at the agent.
- Ingestion points: The skill processes any written content provided by the user, as specified in the 'When to Use This Skill' section of
SKILL.md. - Boundary markers: The instructions do not define specific delimiters or warnings to ignore commands embedded within the text to be edited.
- Capability inventory: No scripts or external tools are included in the skill; it relies entirely on natural language instructions for text transformation.
- Sanitization: There is no logic for sanitizing or filtering instructions that might be present in the user-supplied prose.
Audit Metadata