writing-beats
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes raw markdown material provided by the user to generate content beats. This creates an ingestion surface where instructions embedded within the raw text could attempt to manipulate the agent's output or actions.
- Ingestion points: The skill reads raw material from a markdown file provided by the user, as described in the
SKILL.mdinstructions. - Boundary markers: There are no explicit instructions or delimiters defined within the skill to separate the raw content from the agent's core instructions or to ignore embedded commands.
- Capability inventory: The skill is authorized to read from and write to the local file system, as it requires a path to save the article and re-reads the file from disk periodically.
- Sanitization: The instructions do not specify any validation, filtering, or sanitization of the content extracted from the raw material before it is processed or written to the output file.
Audit Metadata