writing-beats

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-supplied markdown files ("raw material") which represents a potential surface for indirect prompt injection.
  • Ingestion points: The instructions in SKILL.md direct the agent to process a user-provided markdown file as a source for generating writing "beats".
  • Boundary markers: The skill does not define clear delimiters or "ignore" instructions for the content of the raw material, increasing the risk that instructions embedded in the user data could be followed by the agent.
  • Capability inventory: The agent is tasked with reading from and writing to files based on the content of the ingested data, which could be abused if the input material contains malicious instructions.
  • Sanitization: There is no mention of validating, escaping, or sanitizing the input material to ensure it does not contain commands meant to redirect the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 11:11 AM
Security Audit — agent-trust-hub — writing-beats