about-me
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill performs legitimate personalization tasks by collecting user input and writing it to a local file. No unauthorized network access, remote code execution, or persistence mechanisms were detected. The skill guides the agent through a structured process to ensure high-quality, personalized output based on human-provided context.
- [PROMPT_INJECTION]: The skill ingests raw user text and writing samples without explicit boundary markers or sanitization steps. This creates a surface for indirect prompt injection where instructions embedded in the user's samples could influence the agent's synthesis process. Evidence: Workflow Step 1 and Step 1.5 in SKILL.md. Given the skill's purpose and limited capabilities (file-write only), this is considered a minor risk that does not compromise the security of the execution environment.
Audit Metadata