content-strategy

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from multiple external sources, creating a vector for indirect prompt injection attacks.\n
  • Ingestion points: The skill instructions in SKILL.md direct the agent to analyze user-provided keyword exports, sales call transcripts, customer survey responses, and search results from public platforms like Reddit and Quora.\n
  • Boundary markers: The instructions do not define specific delimiters or "ignore" warnings to prevent the agent from following malicious instructions that might be embedded in the analyzed data.\n
  • Capability inventory: The skill lacks high-risk capabilities like network exfiltration, arbitrary command execution, or file system modifications, which serves as a significant mitigating factor.\n
  • Sanitization: No explicit sanitization or filtering logic is provided for the data being ingested from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:32 PM
Security Audit — agent-trust-hub — content-strategy