sponsor-pitch-generator
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the user to paste external content (brand inquiries) to generate responses. This creates a surface where the agent processes untrusted data which could contain malicious instructions.
- Ingestion points: External text input in the "How to Use" section for brand inquiries.
- Boundary markers: Absent; the instructions do not specify delimiters for the pasted content.
- Capability inventory: No tools, scripts, network access, or file-writing capabilities are present in the skill.
- Sanitization: None; the skill relies on the agent's default processing of text.
- [NO_CODE]: The skill contains only Markdown documentation and text templates. No executable scripts (.py, .js, .sh), package dependencies, or automated commands are included.
Audit Metadata