copy-editing

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and systematically process untrusted data provided by users during the editing process.
  • Ingestion points: Processes user-provided marketing copy for editing (SKILL.md); reads local project files at .agents/product-marketing-context.md or .claude/product-marketing-context.md (SKILL.md).
  • Boundary markers: Absent. The instructions do not mandate the use of XML tags, delimiters, or specific instructions to ignore embedded commands within the input text.
  • Capability inventory: File system read access for context files; generation of text based on processed input.
  • Sanitization: Absent. No filtering or validation of the input text is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 11:48 PM
Security Audit — agent-trust-hub — copy-editing