write-review-artifact
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external draft content from
corpus/drafts/{slug}.md. While this ingestion point creates a theoretical surface for indirect prompt injection, the rigid output schema and strict formatting rules provide significant constraints. - Ingestion points: Draft files located at
corpus/drafts/{slug}.md. - Boundary markers: Not explicitly defined in the template.
- Capability inventory: Writing reviewed artifacts to the
ops/technical-reviewer/directory. - Sanitization: No explicit sanitization or escaping of ingested content is mentioned.
- [SAFE]: No malicious patterns such as remote code execution, obfuscation, or data exfiltration were detected. The instructions are focused on maintaining reporting standards and artifact integrity.
Audit Metadata