copy-editing
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and systematically process untrusted data provided by users during the editing process.
- Ingestion points: Processes user-provided marketing copy for editing (SKILL.md); reads local project files at
.agents/product-marketing-context.mdor.claude/product-marketing-context.md(SKILL.md). - Boundary markers: Absent. The instructions do not mandate the use of XML tags, delimiters, or specific instructions to ignore embedded commands within the input text.
- Capability inventory: File system read access for context files; generation of text based on processed input.
- Sanitization: Absent. No filtering or validation of the input text is implemented.
Audit Metadata