newsletter-coach

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted data from user "brain dumps" and daily experiences, creating a surface for indirect prompt injection.\n
  • Ingestion points: Untrusted data enters the agent context through user responses in Phase 1 ("GET THE ACTIONS AND DECISIONS") and the opening conversation, as well as via results from the WebSearch and WebFetch tools (found in SKILL.md).\n
  • Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings for the agent when it interpolates user-provided stories or fetched web content into its drafting process.\n
  • Capability inventory: The agent has capabilities including file system access (Read, Glob), network operations (WebSearch, WebFetch), and the ability to trigger external functionality by invoking other skills such as hook-stack-evaluator, ai-slop-detector, and nano-banana-pro (found in SKILL.md).\n
  • Sanitization: There are no documented steps for sanitizing, validating, or escaping user-provided or web-fetched content before it is used to generate headlines and article drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:04 AM
Security Audit — agent-trust-hub — newsletter-coach