content-strategy
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and analyze untrusted data from multiple sources including web search results (Reddit, Quora, competitor blogs), sales call transcripts, and survey responses.
- Ingestion points: Instructions in
SKILL.md(and localized variants) direct the agent to process keyword exports, transcript files, and perform web searches to extract FAQs and terminology. - Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings when processing these external data sources.
- Capability inventory: The skill uses web search capabilities but does not request or utilize dangerous tools such as shell execution, network writes, or file system modifications.
- Sanitization: No sanitization or validation logic is defined for the external content before it is processed by the agent.
Audit Metadata