blog-writer

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown-based instructions and configuration. It does not contain any scripts, binaries, or shell commands.
  • [PROMPT_INJECTION]: The skill defines a configuration hierarchy where settings in a user-swappable 'voice-profile.md' file override the core engine. This is a functional design choice for styling and does not represent an attempt to bypass platform safety guidelines.
  • [PROMPT_INJECTION]: The skill processes untrusted user-supplied content to generate blog posts, creating a surface for indirect prompt injection.
  • Ingestion points: SKILL.md instructs the agent to ingest 'raw material' (e.g., numbers, incidents, code) and 'existing pieces of writing' from the user to inform the generation process. It also reads style configuration from 'voice-profile.md'.
  • Boundary markers: Absent. The instructions do not define specific delimiters to isolate user-provided data from the agent's internal logic.
  • Capability inventory: The skill possesses no capabilities for network requests, file system modification, or shell command execution.
  • Sanitization: Absent.
  • Summary: Although the skill lacks sanitization and boundary markers for user-provided data, the absence of sensitive capabilities (network, write, exec) prevents this surface from being exploited for high-impact malicious actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 06:06 AM
Security Audit — agent-trust-hub — blog-writer