wordcamp-event-recap
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external WordCamp websites, schedules, and user notes, which are untrusted sources that could contain malicious instructions.
- Ingestion points: The skill retrieves content from WordCamp URLs, schedule pages, news blogs, and keynote transcripts/captions using the agent's live browsing tools (documented in SKILL.md).
- Boundary markers: The skill uses a logical "source bank" and "quote ledger" system to reconcile data, but does not specify technical delimiters (like XML tags) to separate untrusted content from the system prompt.
- Capability inventory: The agent's capabilities within this skill are focused on web browsing and text drafting; it does not request or use dangerous shell execution, file system modification, or privilege escalation tools.
- Sanitization: The skill mandates a "Humanizer pass" to strip AI-typical patterns and a detailed "Self-edit checklist" to ensure the output matches the provided notes rather than blindly following instructions that might be embedded in the external pages.
Audit Metadata