writing-for-routine

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data ("grill answers") to generate subsequent prompt files and automated routines.
  • Ingestion points: The agent is instructed to read "grill answers" in the first step of the process to determine the content of the generated prompt.
  • Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore instructions within the grill data, which could allow malicious input to influence the generated prompt.md file.
  • Capability inventory: The skill has the capability to write and overwrite local files, including prompt.md, handoff.md, and Fixed-step Skill files.
  • Sanitization: The instructions do not specify any validation or sanitization requirements for the external data before it is interpolated into the generated prompt structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 01:37 PM
Security Audit — agent-trust-hub — writing-for-routine