humanize-writing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user-supplied content, such as text drafts and writing samples, to perform humanization and rewriting tasks. It lacks explicit instructions for the agent to use boundary markers or delimiters (e.g., XML tags or specific separators) to isolate the user input from its own instructional context. This creates a surface where a malicious user could potentially embed instructions within their draft to influence the agent's behavior. However, the skill's scope is restricted to text editing and it does not utilize high-risk capabilities like network access or shell execution.\n
  • Ingestion points: Identified in SKILL.md where the agent is instructed to handle user-shared text, drafts, and writing samples.\n
  • Boundary markers: Absent; the instructions do not specify the use of delimiters for user data.\n
  • Capability inventory: The skill is limited to text analysis and rewriting; no network operations or command execution tools were identified.\n
  • Sanitization: Not defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:08 PM
Security Audit — agent-trust-hub — humanize-writing