pr-pitch-writer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an instructional template for drafting personalized emails. It follows standard agent design patterns, utilizing local knowledge files and writing to designated output directories.
  • [DATA_EXPOSURE]: File access is restricted to the skill's own directory structure (knowledge/ and output/). There are no attempts to access sensitive system files, environment variables, or private credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where external content (journalist articles) is fetched and processed. It includes robust internal safeguards, instructing the agent to never characterize or quote material it has not successfully read and to use placeholders ([NEEDS INPUT]) for missing data. These constraints effectively mitigate risks associated with untrusted external data.
  • [COMMAND_EXECUTION]: The skill uses platform-integrated tools like WebFetch for reading web content, but does not execute arbitrary shell commands or attempt to bypass system security boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:28 AM
Security Audit — agent-trust-hub — pr-pitch-writer