writing-shape
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill operates on untrusted external markdown files and has file system access, which presents a surface for indirect prompt injection.\n
- Ingestion points: The skill reads a 'raw material' markdown file provided by the user as its primary data source (SKILL.md).\n
- Boundary markers: There are no instructions to use specific delimiters (like XML tags or unique markers) to separate the untrusted input text from the system instructions.\n
- Capability inventory: The skill includes instructions to read from the disk and append/write paragraphs to an article file (SKILL.md).\n
- Sanitization: The skill lacks logic to sanitize or filter the content of the input pile for embedded malicious instructions.
Audit Metadata