Content Creator
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to run local scripts
brand_voice_analyzer.pyandseo_optimizer.py, as well as system tools likegrep. These actions are scoped to the skill's purpose and are documented in the metadata. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes untrusted user-supplied content for analysis.
- Ingestion points: The scripts
brand_voice_analyzer.pyandseo_optimizer.pytake file paths as input to process external content (SKILL.md). - Boundary markers: No explicit markers or instructions are provided to the agent to treat the ingested file content as data only or to ignore embedded instructions.
- Capability inventory: The skill utilizes command execution for script processing and file manipulation (SKILL.md).
- Sanitization: There is no documentation of input sanitization or validation of the text being analyzed.
Audit Metadata