reader-first-prose

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of natural language instructions and examples in Markdown format. It does not contain any executable scripts, shell commands, or tool definitions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and transform user-provided prose.
  • Ingestion points: The skill processes arbitrary text provided by users for the purpose of rewriting.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands in the source text.
  • Capability inventory: The skill has no capabilities beyond text transformation; it lacks network access, file system access, or shell execution tools.
  • Sanitization: No specific sanitization or filtering logic is applied to the input text. While the skill processes untrusted input, the lack of any actionable tools or external capabilities renders the injection surface benign.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:36 PM
Security Audit — agent-trust-hub — reader-first-prose