thought-leadership-writer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources and user inputs to generate long-form articles, which creates a potential surface for indirect prompt injection. \n- Ingestion points: The skill reads from multiple files in the knowledge/ directory (voice.md, positioning.md, competitors.md, personas.md, and the content-library/ folder) and processes a user-provided Thesis. \n- Boundary markers: The instructions do not mandate the use of specific delimiters or delimiters combined with instructions to ignore embedded commands within the ingested text. \n- Capability inventory: The skill is capable of writing generated content to the output/thought-leadership/ directory. \n- Sanitization: While the skill instructs the agent to verify sources and mark missing information with [SOURCE NEEDED], it lacks rigorous sanitization or filtering for instructions that might be embedded in the knowledge files.
Audit Metadata