drafting-writing

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process raw text from external files which could contain untrusted instructions.\n- Ingestion points: shaping-session.md reads an 'input pile' which can include transcripts and unstructured prose. SKILL.md requires the agent to 'Re-read the file before each write' to incorporate user edits.\n- Boundary markers: The instructions do not define specific delimiters or guardrails to prevent the agent from following instructions embedded within the processed text.\n- Capability inventory: The skill has the capability to write to local files, specifically appending fragments and drafts to markdown files as specified in fragment-mining.md and shaping-session.md.\n- Sanitization: No sanitization or filtering logic is prescribed for the content read from external files before it is processed or written back to the workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 04:07 PM