meta-compliance-audit-bundle

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing untrusted data from the deep-research skill and passing it to downstream file-writing and memory-storage capabilities.
  • Ingestion points: The skill ingests data via user_message and the output of the research step (outputs.research).
  • Boundary markers: The skill does not employ delimiters or explicit instructions to ignore embedded commands when interpolating research results into the Word document or memory storage.
  • Capability inventory: The skill possesses file-writing capabilities via the docx and html-to-pdf skills and uses the memory_save tool to append data to the local file system.
  • Sanitization: While basic XML escaping is applied during PDF generation, no validation or escaping is performed on data written to the Word report or the persistent memory file, which could allow malicious content from research sources to influence future agent interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 01:08 AM
Security Audit — agent-trust-hub — meta-compliance-audit-bundle