writing-shape

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided markdown files as its primary input, creating a surface for indirect prompt injection where malicious instructions could be embedded in the raw material.\n
  • Ingestion points: User-provided markdown files described as 'the pile' in SKILL.md.\n
  • Boundary markers: Absent. The skill instructions do not establish clear delimiters or provide instructions to ignore content that appears to be a command.\n
  • Capability inventory: The skill performs filesystem read and write/append operations as outlined in SKILL.md.\n
  • Sanitization: Absent. There is no requirement for the agent to sanitize or validate the content extracted from the input files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:52 PM
Security Audit — agent-trust-hub — writing-shape