newsletter-writer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources, creating a potential surface for adversarial influence on agent behavior. \n- Ingestion points: The skill reads 'source material' such as drafts, links, and data points provided by the user, and specifically fetches URLs to validate them during the writing process (SKILL.md). \n- Boundary markers: There are no defined delimiters or instructions to treat external data as untrusted content separate from the agent's core instructions. \n- Capability inventory: The skill is configured to read from the knowledge base (brand, personas, content library), write newsletter files to local storage (output/newsletter/), and perform network requests to resolve external URLs. \n- Sanitization: While the skill performs link resolution checks, it does not implement specific security sanitization or filtering of the content retrieved or processed from external sources to prevent prompt injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:28 AM
Security Audit — agent-trust-hub — newsletter-writer