thought-leadership-writer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources and user inputs to generate long-form articles, which creates a potential surface for indirect prompt injection. \n- Ingestion points: The skill reads from multiple files in the knowledge/ directory (voice.md, positioning.md, competitors.md, personas.md, and the content-library/ folder) and processes a user-provided Thesis. \n- Boundary markers: The instructions do not mandate the use of specific delimiters or delimiters combined with instructions to ignore embedded commands within the ingested text. \n- Capability inventory: The skill is capable of writing generated content to the output/thought-leadership/ directory. \n- Sanitization: While the skill instructs the agent to verify sources and mark missing information with [SOURCE NEEDED], it lacks rigorous sanitization or filtering for instructions that might be embedded in the knowledge files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:28 AM
Security Audit — agent-trust-hub — thought-leadership-writer