blog
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external data and user input to generate content that is written to the file system, creating a surface for indirect prompt injection.- Ingestion points: The workflow ingests data from external tools like
capture-receiptandclose-day, as well as user-provided topics or titles.- Boundary markers: No explicit delimiters or instructions to ignore potential commands within the input data are defined in the skill instructions.- Capability inventory: The skill is capable of reading local files for research purposes and writing drafted articles to `1 - Projects/Public Technical Presence/Public Technical Presence.md`.- Sanitization: There are no specified mechanisms for sanitizing or validating the input data before it is processed and written to the project files.
Audit Metadata