productivity-briefing
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources, creating a surface for indirect prompt injection attacks. \n
- Ingestion points: News platforms (e.g., NAVER, Bloomberg, TechCrunch), competitor websites, and job boards referenced in the workflow sections. \n
- Boundary markers: Absent. The instructions do not define delimiters or directives to the agent to treat external content as untrusted data. \n
- Capability inventory: The skill includes instructions to write reports to the local file system at
.moai/briefings/. \n - Sanitization: Absent. No mention of filtering, escaping, or validating the external content before processing or interpolation. \n- [PROMPT_INJECTION]: The skill contains a section titled 'Information war' (정보전) which instructs on deceptive practices, including social engineering tactics such as pretending to be a potential customer to obtain non-public information from competitors. These instructions encourage the agent to facilitate deceptive behaviors.
Audit Metadata