wordcamp-event-recap

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external WordCamp websites, schedules, and user notes, which are untrusted sources that could contain malicious instructions.
  • Ingestion points: The skill retrieves content from WordCamp URLs, schedule pages, news blogs, and keynote transcripts/captions using the agent's live browsing tools (documented in SKILL.md).
  • Boundary markers: The skill uses a logical "source bank" and "quote ledger" system to reconcile data, but does not specify technical delimiters (like XML tags) to separate untrusted content from the system prompt.
  • Capability inventory: The agent's capabilities within this skill are focused on web browsing and text drafting; it does not request or use dangerous shell execution, file system modification, or privilege escalation tools.
  • Sanitization: The skill mandates a "Humanizer pass" to strip AI-typical patterns and a detailed "Self-edit checklist" to ensure the output matches the provided notes rather than blindly following instructions that might be embedded in the external pages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:35 PM
Security Audit — agent-trust-hub — wordcamp-event-recap