writing-shape
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided markdown files as its primary input, creating a surface for indirect prompt injection where malicious instructions could be embedded in the raw material.\n
- Ingestion points: User-provided markdown files described as 'the pile' in
SKILL.md.\n - Boundary markers: Absent. The skill instructions do not establish clear delimiters or provide instructions to ignore content that appears to be a command.\n
- Capability inventory: The skill performs filesystem read and write/append operations as outlined in
SKILL.md.\n - Sanitization: Absent. There is no requirement for the agent to sanitize or validate the content extracted from the input files.
Audit Metadata