content-manager
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill leverages the Bash tool to execute various local Python utility scripts, such as analyze_references.py and extract_themes.py, to facilitate project orchestration and data processing.
- [PROMPT_INJECTION]: As the skill is designed to analyze external reference materials and transcripts, it possesses a standard surface for indirect prompt injection. Ingestion points: Content enters the agent context through the 'references/' directory and results from web tools. Boundary markers: No specific delimiters or instructions to ignore embedded commands are specified in the current workflow. Capability inventory: The agent has access to tools including 'Bash', 'Read', and 'Write'. Sanitization: The instructions do not specify any explicit sanitization or filtering logic for data ingested from transcripts or search results.
Audit Metadata