writing-for-routine
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data ("grill answers") to generate subsequent prompt files and automated routines.
- Ingestion points: The agent is instructed to read "grill answers" in the first step of the process to determine the content of the generated prompt.
- Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore instructions within the grill data, which could allow malicious input to influence the generated
prompt.mdfile. - Capability inventory: The skill has the capability to write and overwrite local files, including
prompt.md,handoff.md, and Fixed-step Skill files. - Sanitization: The instructions do not specify any validation or sanitization requirements for the external data before it is interpolated into the generated prompt structure.
Audit Metadata