skills/smixs/seo-blog/blog/Gen Agent Trust Hub

blog

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection through its core functionalities.
  • Ingestion points: The /blog analyze <file-or-url> and /blog rewrite <file> commands read external content from user-provided files or URLs, which are then processed by the blog-reviewer and blog-writer agents.
  • Boundary markers: The skill instructions and templates lack explicit delimiters or mandatory 'ignore embedded instructions' prompts when interpolating external content into the agent's context, increasing the risk that the LLM will follow malicious instructions found in the ingested text.
  • Capability inventory: The skill environment grants high-privilege tools including Write, Edit, Bash, and WebFetch, which could be abused if an injection attack succeeds.
  • Sanitization: There is no evidence of sanitization, escaping, or validation logic to filter out natural language instructions from the external data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:56 PM
Security Audit — agent-trust-hub — blog