reframe-voice

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions that explicitly attempt to override existing behavioral constraints. Specifically, the documentation states that the skill's voice specification "takes precedence over general writing-style guidance" and should be followed "even where they collide with standing plain-style or banned-phrase rules." While this is contextually limited to writing style, the instruction to disregard standing rules is a known injection pattern.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user-supplied data for rewriting and review, creating a potential surface for indirect instructions to influence agent behavior.
  • Ingestion points: User-provided content intended for writing, rewriting, or review as specified in SKILL.md.
  • Boundary markers: Absent. The skill does not define delimiters or provide specific instructions to the agent to ignore embedded commands within the user-supplied text.
  • Capability inventory: The skill operates in an environment with access to file system tools such as Read, Write, Edit, Grep, and Glob (as limited by the platform's allowed-tools configuration).
  • Sanitization: Absent. The instructions do not include methods for validating, filtering, or escaping external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:02 PM
Security Audit — agent-trust-hub — reframe-voice