repurpose-talk
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions prompt the agent to read
~/.devadvokit.md, a hidden configuration file in the user's home directory, and../../shared/ai-antipatterns.md, a shared style guide. These files are accessed silently to provide context and perform quality checks on the generated output. While these paths are external to the skill's specific folder, they appear to be standard configuration and style resources for the intended environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes talk transcripts, abstracts, and speaker notes provided by the user to generate content.
- Ingestion points: Talk transcripts, abstracts, and notes pasted or provided via file paths in the Q&A section of
SKILL.md. - Boundary markers: The instructions do not use specific delimiters or protective instructions to wrap the user-supplied content, which is a potential surface for indirect prompt injection.
- Capability inventory: The skill does not involve any shell command execution, file writing, or network operations, effectively mitigating the risk of exploitation from malicious content inside a transcript.
- Sanitization: No explicit sanitization or filtering is performed on the ingested text before it is used for content generation.
Audit Metadata