content-strategy
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from multiple external sources, creating a vector for indirect prompt injection attacks.\n
- Ingestion points: The skill instructions in
SKILL.mddirect the agent to analyze user-provided keyword exports, sales call transcripts, customer survey responses, and search results from public platforms like Reddit and Quora.\n - Boundary markers: The instructions do not define specific delimiters or "ignore" warnings to prevent the agent from following malicious instructions that might be embedded in the analyzed data.\n
- Capability inventory: The skill lacks high-risk capabilities like network exfiltration, arbitrary command execution, or file system modifications, which serves as a significant mitigating factor.\n
- Sanitization: No explicit sanitization or filtering logic is provided for the data being ingested from external sources.
Audit Metadata