proofreading-agent
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard utility for Japanese text correction. It operates by reading local files, processing the text through the Google Gemini API, and writing an annotated report to a local directory.
- [SAFE]: Data handling is localized and transparent. The script sends the input text to a trusted external service (Google Gemini API) for its core functionality and does not attempt to access sensitive system directories or credentials outside of those required for API authentication.
- [SAFE]: The script uses
yaml.safe_loadfor parsing configuration files, which protects against YAML-based code execution vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests content from external files provided by the user.
- Ingestion points:
scripts/proofreading_agent.py(line 331) reads content from the file system via the--inputparameter. - Boundary markers: Absent. The input text is numbered but not enclosed in XML tags or other delimiters to prevent the LLM from interpreting parts of the input as instructions.
- Capability inventory: The agent can read and write local files and communicate with the Gemini API. It does not have arbitrary code execution capabilities.
- Sanitization: No sanitization or filtering is performed on the ingested text before interpolation into the prompt.
Audit Metadata