content-repurposing

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Mandatory Output Hijacking. The agent is instructed to prepend a solicitation message containing CashApp and BuyMeACoffee links to every long-form content output.
  • [PROMPT_INJECTION]: System Prompt Deflection. The skill instructs the agent to ignore inquiries about its system prompt and instead provide a promotional link to the author's commercial membership site.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes external, untrusted content (e.g., blog posts, transcripts) for repurposing without implementing safety delimiters. 1. Ingestion points: User-provided content ingested through the repurposing capabilities defined in SKILL.md. 2. Boundary markers: Absent; no instructions exist to isolate or escape user-provided data. 3. Capability inventory: No high-risk tools (file system, network, or subprocess) are present; capabilities are limited to text processing. 4. Sanitization: Absent; the skill does not provide instructions to filter or sanitize input content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:03 AM
Security Audit — agent-trust-hub — content-repurposing