create-title

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it incorporates untrusted external data retrieved through web search and fetch tools into the agent's context.\n
  • Ingestion points: Data entering the context from external URLs via WebSearch and WebFetch queries in Step 2 of the research workflow (SKILL.md).\n
  • Boundary markers: The instructions do not define clear delimiters or provide 'ignore embedded instructions' directives for the processing of external research data.\n
  • Capability inventory: The skill can generate content suggestions and influence the use of subsequent skills (like /create-description or /create-hashtags) based on the processed data.\n
  • Sanitization: There are no documented steps for sanitizing, escaping, or validating the content retrieved from external websites before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 04:20 PM
Security Audit — agent-trust-hub — create-title