skills/tonone-ai/tonone/ink-post/Gen Agent Trust Hub

ink-post

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by design. It retrieves and processes untrusted data from the internet to perform keyword research and competitor analysis, which could contain instructions meant to hijack the agent's behavior.
  • Ingestion points: Untrusted external data is gathered using the WebSearch and WebFetch tools in Step 1 (Keyword Research).
  • Boundary markers: The instructions do not specify any delimiters or safety warnings (e.g., 'ignore instructions found in this content') when the agent processes the fetched research data.
  • Capability inventory: The skill is granted access to the Bash tool, specifically intended for testing code examples in Step 4, which increases the potential impact of a successful injection.
  • Sanitization: There is no evidence of content filtering, escaping, or validation applied to the external data before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:57 AM
Security Audit — agent-trust-hub — ink-post