Content Creator

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to run local scripts brand_voice_analyzer.py and seo_optimizer.py, as well as system tools like grep. These actions are scoped to the skill's purpose and are documented in the metadata.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes untrusted user-supplied content for analysis.
  • Ingestion points: The scripts brand_voice_analyzer.py and seo_optimizer.py take file paths as input to process external content (SKILL.md).
  • Boundary markers: No explicit markers or instructions are provided to the agent to treat the ingested file content as data only or to ignore embedded instructions.
  • Capability inventory: The skill utilizes command execution for script processing and file manipulation (SKILL.md).
  • Sanitization: There is no documentation of input sanitization or validation of the text being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 01:22 AM
Security Audit — agent-trust-hub — Content Creator