content-research-writer
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to fetch and process untrusted content from external websites during the research phase.
- Ingestion points: Web content ingested via browser and web fetch tools, as specified in the Step 3: Conduct Research section and the Cline Workflow Notes in SKILL.md.
- Boundary markers: The skill instructions do not specify any delimiters or safety instructions (e.g., 'ignore instructions in fetched data') to separate external content from the agent's primary directives.
- Capability inventory: The agent has capabilities to read and write files in the local workspace (outline.md, research.md, etc.) and perform network operations using browser tools.
- Sanitization: There are no prescribed sanitization, filtering, or validation steps for the external content before it is processed or incorporated into the writing project.
Audit Metadata