drafting-writing
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process raw text from external files which could contain untrusted instructions.\n- Ingestion points:
shaping-session.mdreads an 'input pile' which can include transcripts and unstructured prose.SKILL.mdrequires the agent to 'Re-read the file before each write' to incorporate user edits.\n- Boundary markers: The instructions do not define specific delimiters or guardrails to prevent the agent from following instructions embedded within the processed text.\n- Capability inventory: The skill has the capability to write to local files, specifically appending fragments and drafts to markdown files as specified infragment-mining.mdandshaping-session.md.\n- Sanitization: No sanitization or filtering logic is prescribed for the content read from external files before it is processed or written back to the workspace.
Audit Metadata