reframe-voice
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions that explicitly attempt to override existing behavioral constraints. Specifically, the documentation states that the skill's voice specification "takes precedence over general writing-style guidance" and should be followed "even where they collide with standing plain-style or banned-phrase rules." While this is contextually limited to writing style, the instruction to disregard standing rules is a known injection pattern.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user-supplied data for rewriting and review, creating a potential surface for indirect instructions to influence agent behavior.
- Ingestion points: User-provided content intended for writing, rewriting, or review as specified in
SKILL.md. - Boundary markers: Absent. The skill does not define delimiters or provide specific instructions to the agent to ignore embedded commands within the user-supplied text.
- Capability inventory: The skill operates in an environment with access to file system tools such as
Read,Write,Edit,Grep, andGlob(as limited by the platform'sallowed-toolsconfiguration). - Sanitization: Absent. The instructions do not include methods for validating, filtering, or escaping external content before it is processed by the agent.
Audit Metadata