positioning-messaging-designer
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process untrusted external data, such as customer interview transcripts, call notes, and 'SPICED' data, to extract messaging elements. This creates a surface for indirect prompt injection if the source data contains malicious instructions.
- Ingestion points: External data is ingested in Part 2 ('Building the Canvas') and the 'LLM-Assisted Positioning' section (loading transcripts/notes).
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the processed data.
- Capability inventory: The skill is primarily instructional and does not demonstrate use of dangerous tools like arbitrary command execution, network requests to untrusted domains, or file system writes.
- Sanitization: No specific sanitization or filtering logic is mentioned for the ingested qualitative data.
Audit Metadata