Creative Intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core function of retrieving and processing untrusted data from the internet.
- Ingestion points: The skill utilizes
WebSearchfor market and competitive research andWebFetchto download external documentation and articles from the web. - Boundary markers: The instructions do not define specific delimiters or boundary markers to differentiate between the agent's instructions and untrusted content fetched from the web.
- Capability inventory: The skill possesses the capability to write to the file system using the
TodoWritetool and can execute complex workflows via theTask toolsubagent. - Sanitization: There are no explicit instructions or mechanisms described for the sanitization, validation, or filtering of content retrieved from external sources before it is processed by the agent.
Audit Metadata