06-ugc-egc-brief-global

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a vulnerability surface for indirect prompt injection as it processes and interpolates user-supplied data into marketing templates without specific guardrails or sanitization.\n- Ingestion points: Information gathering phase in SKILL.md (product info, target customers, and product links).\n- Boundary markers: None present; the skill lack explicit delimiters to isolate untrusted user data from agent instructions.\n- Capability inventory: None; the skill consists entirely of instructional text and templates and does not invoke any file system or network tools.\n- Sanitization: No validation, escaping, or filtering of the gathered user input is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:39 PM
Security Audit — agent-trust-hub — 06-ugc-egc-brief-global