specialist-marketing-content-creator
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input by directly interpolating it into a sub-agent prompt. \n- Ingestion points: The
{the user's question}variable inSKILL.mdacts as an entry point for external data. \n- Boundary markers: There are no delimiters (e.g., XML tags, triple backticks) or system instructions to separate the user query from the sub-agent's core instructions. \n- Capability inventory: The skill utilizes theAgenttool to spawn ephemeral specialist agents, providing a pathway for injected instructions to reach other agent instances. \n- Sanitization: No input validation or escaping is applied to the user's question before processing.
Audit Metadata