content-strategy

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and analyze untrusted data from multiple sources including web search results (Reddit, Quora, competitor blogs), sales call transcripts, and survey responses.
  • Ingestion points: Instructions in SKILL.md (and localized variants) direct the agent to process keyword exports, transcript files, and perform web searches to extract FAQs and terminology.
  • Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings when processing these external data sources.
  • Capability inventory: The skill uses web search capabilities but does not request or utilize dangerous tools such as shell execution, network writes, or file system modifications.
  • Sanitization: No sanitization or validation logic is defined for the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:58 AM
Security Audit — agent-trust-hub — content-strategy