writing-shape
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating a surface for indirect prompt injection. \n- Ingestion points: The agent reads a user-supplied 'raw material markdown file' as its primary input in SKILL.md. \n- Boundary markers: The instructions do not include specific delimiters or directives to ignore instructions potentially embedded within the input material. \n- Capability inventory: The skill has file-reading and file-appending capabilities during its operation. \n- Sanitization: There is no explicit sanitization or filtering of the content extracted from the input pile before it is integrated into the output article.
Audit Metadata