summarize-anything
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize untrusted external data such as articles, emails, and transcripts. This creates a potential surface for indirect prompt injection where malicious instructions embedded within the source text could attempt to influence the agent's output. However, the risk is minimal as the skill has no access to sensitive tools, files, or network resources.
- Ingestion points: The skill processes external content provided by the user as 'The source' (defined in SKILL.md).
- Boundary markers: The instructions do not define clear delimiters or include warnings to ignore instructions embedded in the source text.
- Capability inventory: The skill's functionality is limited to text generation; it has no capabilities for file modification, network access, or command execution.
- Sanitization: There is no evidence of input filtering or sanitization.
Audit Metadata