writing-fragments
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is designed to read and process content from a local markdown file that can be modified by the user or other processes.\n
- Ingestion points: As defined in
SKILL.md, the agent is instructed to "re-read the file from disk" before every write operation to preserve user edits.\n - Boundary markers: The skill does not implement delimiters or specific instructions to the agent to disregard any commands or instructions found within the file being read.\n
- Capability inventory: The skill has access to file system read and write capabilities to manage the fragment file.\n
- Sanitization: No sanitization, validation, or filtering of the file content is mentioned or implemented before the agent processes the retrieved text.
Audit Metadata