paw-wbc-agent-producer

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is processing local project files for content generation. It interacts with configuration and research files within the .pawbytes directory, which aligns with its stated purpose. It does not attempt to access sensitive system files, execute shell commands, or perform network operations.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it ingests untrusted data from discovery outputs. Evidence for this surface includes: 1. Ingestion points: brief.md, research-context.md, and hook-selected.md from the webinar workspace. 2. Boundary markers: The instructions do not specify explicit delimiters or 'ignore embedded instructions' warnings for the research data. 3. Capability inventory: Capabilities are restricted to reading project context and writing markdown documents (slide-deck-outline.md, script.md, recommendations.md). No network or system-level tools are available to the skill. 4. Sanitization: No explicit validation or filtering of external content is mentioned. Risk Assessment: The lack of high-risk capabilities significantly limits the potential for exploitation via injection.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 01:55 PM
Security Audit — agent-trust-hub — paw-wbc-agent-producer