content-manager

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages the Bash tool to execute various local Python utility scripts, such as analyze_references.py and extract_themes.py, to facilitate project orchestration and data processing.
  • [PROMPT_INJECTION]: As the skill is designed to analyze external reference materials and transcripts, it possesses a standard surface for indirect prompt injection. Ingestion points: Content enters the agent context through the 'references/' directory and results from web tools. Boundary markers: No specific delimiters or instructions to ignore embedded commands are specified in the current workflow. Capability inventory: The agent has access to tools including 'Bash', 'Read', and 'Write'. Sanitization: The instructions do not specify any explicit sanitization or filtering logic for data ingested from transcripts or search results.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 04:50 AM
Security Audit — agent-trust-hub — content-manager