writing-fragments

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is designed to read and process content from a local markdown file that can be modified by the user or other processes.\n
  • Ingestion points: As defined in SKILL.md, the agent is instructed to "re-read the file from disk" before every write operation to preserve user edits.\n
  • Boundary markers: The skill does not implement delimiters or specific instructions to the agent to disregard any commands or instructions found within the file being read.\n
  • Capability inventory: The skill has access to file system read and write capabilities to manage the fragment file.\n
  • Sanitization: No sanitization, validation, or filtering of the file content is mentioned or implemented before the agent processes the retrieved text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — writing-fragments