copy-review

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided marketing copy (emails, ads, web pages). While this creates an ingestion point for external data, the risk is addressed through structured processing. The instructions require the agent to quote original lines specifically and provide a structured output format, which acts as a natural boundary. The skill lacks dangerous capabilities such as network exfiltration or shell execution, limiting the impact of any potential injection in the processed copy to the content of the rewrite itself.
  • [SAFE]: The skill operates primarily through sophisticated natural language instructions. It reads from local knowledge files (knowledge/brand/voice.md, knowledge/icp/personas.md) and writes its analysis to a specific local output directory (output/copy-review/). There are no external network calls, remote code executions, or obfuscated patterns detected. The metadata references established literary works (e.g., Zinsser, Ogilvy) which are used for grounding its reasoning logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:28 AM
Security Audit — agent-trust-hub — copy-review