tech-podcast-interview-prep

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external, untrusted sources during its reconnaissance phase.
  • Ingestion points: In Step 1 (Show reconnaissance), the skill directs the agent to fetch and analyze content from the web, including show RSS feeds, Apple Podcasts pages, and general web search results.
  • Boundary markers: The skill does not implement specific delimiters or instructions to treat the external content as untrusted data or to prevent it from overriding the agent's core instructions.
  • Capability inventory: The agent's capabilities within this skill are focused on structured text generation and markdown drafting. It lacks high-risk capabilities such as arbitrary shell execution, system-level file modification, or the ability to exfiltrate sensitive local environment variables to the network.
  • Sanitization: There is no evidence of content sanitization or validation logic to filter out potentially malicious natural language instructions embedded within the external podcast metadata or transcripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — tech-podcast-interview-prep