content-writer

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell script using find to locate its reference documentation (content-writing.md) across multiple user directories including ~/.claude/plugins, ~/.claude/skills, and ~/.codex/skills.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an "audit and rewrite" capability that ingests untrusted data from external URLs (via Firecrawl) and local files.
  • Ingestion points: External content is loaded via the firecrawl/web tool or specified file paths in Step 2 and Step 4.
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within the source text being improved.
  • Capability inventory: The agent has access to shell execution (find), network tools (firecrawl, WebSearch), and image generation tools (mcp__NotFair-GoogleAds__generate_image).
  • Sanitization: There is no evidence of filtering or sanitization of the external content before it is processed by the agent.
  • [SAFE]: References to external domains like notfair.co are intended for documentation and serve as the author's reference material.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:14 PM
Security Audit — agent-trust-hub — content-writer