advisory-edit
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is entirely instructional and defines a non-intrusive editorial workflow. No malicious commands, obfuscated code, or unauthorized access patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data in the form of writer's drafts. Evidence: 1. Ingestion point: User-provided essays and drafts (SKILL.md). 2. Boundary markers: None explicitly defined in the prompt instructions. 3. Capability inventory: The instructions specify the agent lacks Write/Edit tools and is limited to generating text-based critiques. 4. Sanitization: None. Risk is categorized as safe because the agent's autonomy is strictly constrained by the 'advisory-only' rules and limited tool access, preventing the execution of embedded instructions.
Audit Metadata