writing-like-leo

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a 'Voice Calibration' feature that processes user-controlled file paths.
  • Ingestion points: In references/writing/rewriting.md, users are encouraged to provide a file path to the agent (e.g., 'Use my writing style from [file path] as a reference').
  • Boundary markers: The skill lacks delimiters or 'ignore embedded instructions' warnings for the data it processes, making it vulnerable to indirect prompt injection if the referenced file contains malicious instructions.
  • Capability inventory: The skill is designed to read, analyze, and process the contents of local files as part of its core writing task.
  • Sanitization: There is no instruction to validate the provided path or filter the content of the referenced file. This creates a risk where an attacker could provide paths to sensitive system files (e.g., configuration files or credentials) to be read into the agent's context under the guise of style matching.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 12:01 AM
Security Audit — agent-trust-hub — writing-like-leo