tech-podcast-interview-prep
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external, untrusted sources during its reconnaissance phase.
- Ingestion points: In Step 1 (Show reconnaissance), the skill directs the agent to fetch and analyze content from the web, including show RSS feeds, Apple Podcasts pages, and general web search results.
- Boundary markers: The skill does not implement specific delimiters or instructions to treat the external content as untrusted data or to prevent it from overriding the agent's core instructions.
- Capability inventory: The agent's capabilities within this skill are focused on structured text generation and markdown drafting. It lacks high-risk capabilities such as arbitrary shell execution, system-level file modification, or the ability to exfiltrate sensitive local environment variables to the network.
- Sanitization: There is no evidence of content sanitization or validation logic to filter out potentially malicious natural language instructions embedded within the external podcast metadata or transcripts.
Audit Metadata