living-text-style

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell and Python snippets in SKILL.md and references/review-pipeline.md for automated text processing tasks, such as dash normalization and cross-referencing markers across different markdown files.- [EXTERNAL_DOWNLOADS]: In references/community-research.md, the skill provides instructions and code snippets for using browser automation and search tools to fetch data from well-known platforms including Reddit, Hacker News, and GitHub for research purposes.- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by ingesting data from external community forums (Category 8). It explicitly defines an evidence chain to mitigate this risk: 1. Ingestion points: Reddit, Hacker News, and GitHub Issues content (defined in community-research.md). 2. Boundary markers: A mandatory fact-checking table used to distinguish between user-provided data and external findings (defined in per-section-drafting.md). 3. Capability inventory: Local script execution for file normalization and style auditing. 4. Sanitization: Detailed instructions for verifying external data and providing source links for all findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 01:19 PM
Security Audit — agent-trust-hub — living-text-style