thread-writer
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface associated with its content repurposing functionality.\n
- Ingestion points: The skill is designed to ingest and process user-supplied text and external long-form content (e.g., blog posts) to convert them into social media threads, as described in the 'Edge cases' and 'Related skills' sections of SKILL.md.\n
- Boundary markers: While the instructions direct the agent to load brand profiles and voice foundation files as guardrails, they do not prescribe the use of explicit delimiters (e.g., XML tags or block delimiters) to isolate untrusted input content.\n
- Capability inventory: The skill's primary capability is text generation for public social media distribution; it also references external scheduling workflows via third-party services like WoopSocial.\n
- Sanitization: No explicit procedures for sanitizing, validating, or escaping external data are documented within the skill's instructions.\n- [NO_CODE]: No executable code, scripts, or binary files were found within the provided skill files; the skill consists entirely of instructional markdown and configuration.
Audit Metadata