content-research-writer

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to fetch and process untrusted content from external websites during the research phase.
  • Ingestion points: Web content ingested via browser and web fetch tools, as specified in the Step 3: Conduct Research section and the Cline Workflow Notes in SKILL.md.
  • Boundary markers: The skill instructions do not specify any delimiters or safety instructions (e.g., 'ignore instructions in fetched data') to separate external content from the agent's primary directives.
  • Capability inventory: The agent has capabilities to read and write files in the local workspace (outline.md, research.md, etc.) and perform network operations using browser tools.
  • Sanitization: There are no prescribed sanitization, filtering, or validation steps for the external content before it is processed or incorporated into the writing project.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — content-research-writer