sponsor-pitch-generator

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the user to paste external content (brand inquiries) to generate responses. This creates a surface where the agent processes untrusted data which could contain malicious instructions.
  • Ingestion points: External text input in the "How to Use" section for brand inquiries.
  • Boundary markers: Absent; the instructions do not specify delimiters for the pasted content.
  • Capability inventory: No tools, scripts, network access, or file-writing capabilities are present in the skill.
  • Sanitization: None; the skill relies on the agent's default processing of text.
  • [NO_CODE]: The skill contains only Markdown documentation and text templates. No executable scripts (.py, .js, .sh), package dependencies, or automated commands are included.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — sponsor-pitch-generator