to-narration
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from BEATS.md and cited sources, creating a potential vector for indirect prompt injection.
- Ingestion points: BEATS.md and referenced sources (SKILL.md Step 1).
- Boundary markers: Stable anchors -pNN are required for structure, but no explicit prompt boundary markers or ignore-embedded-instruction warnings are defined.
- Capability inventory: The skill is restricted to reading and writing local text files; it performs no network operations, subprocess calls, or dynamic code execution.
- Sanitization: No sanitization, escaping, or validation of the external content is performed before interpolation into the narration output.
Audit Metadata