copywriting-cta

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input from conversation history and direct interview responses to generate marketing copy and recommendations, which defines a potential vulnerability surface.
  • Ingestion points: The agent is instructed to "pull what's available from the conversation" and asks the user five specific questions regarding article context, objectives, audience, funnel stage, and mechanisms using the AskUserQuestion tool (SKILL.md, Step 1).
  • Boundary markers: The instructions lack explicit delimiters or boundary markers to isolate user-provided data from the agent's internal logic, and there are no specific warnings to ignore commands embedded in the user input.
  • Capability inventory: The skill is configured with broad tool access, including Read, Edit, Write, Glob, and Grep (SKILL.md frontmatter). If manipulated by malicious user input, these capabilities could theoretically be used to access or modify the file system outside the intended scope of the skill.
  • Sanitization: No sanitization, validation, or escaping of user-provided inputs is mentioned before the data is used to populate templates and archetypes in the recommendation output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:59 PM
Security Audit — agent-trust-hub — copywriting-cta