Creative Intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core function of retrieving and processing untrusted data from the internet.
  • Ingestion points: The skill utilizes WebSearch for market and competitive research and WebFetch to download external documentation and articles from the web.
  • Boundary markers: The instructions do not define specific delimiters or boundary markers to differentiate between the agent's instructions and untrusted content fetched from the web.
  • Capability inventory: The skill possesses the capability to write to the file system using the TodoWrite tool and can execute complex workflows via the Task tool subagent.
  • Sanitization: There are no explicit instructions or mechanisms described for the sanitization, validation, or filtering of content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 04:49 PM
Security Audit — agent-trust-hub — Creative Intelligence