create-title
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it incorporates untrusted external data retrieved through web search and fetch tools into the agent's context.\n
- Ingestion points: Data entering the context from external URLs via WebSearch and WebFetch queries in Step 2 of the research workflow (SKILL.md).\n
- Boundary markers: The instructions do not define clear delimiters or provide 'ignore embedded instructions' directives for the processing of external research data.\n
- Capability inventory: The skill can generate content suggestions and influence the use of subsequent skills (like /create-description or /create-hashtags) based on the processed data.\n
- Sanitization: There are no documented steps for sanitizing, escaping, or validating the content retrieved from external websites before the agent processes it.
Audit Metadata