xe-writing-style
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest user-provided brain dumps or outlines for transformation into blog posts, which creates a potential surface for indirect prompt injection. 1. Ingestion points: User-provided notes or outlines in the agent's interaction prompt as specified in SKILL.md. 2. Boundary markers: Absent; the instructions do not specify the use of delimiters or XML tags to isolate user input from system instructions. 3. Capability inventory: The agent is limited to reading provided local assets and generating text; no high-risk tools such as shell access, network operations, or filesystem write capabilities are requested or used. 4. Sanitization: No input validation or filtering is performed on the user-provided data.
Audit Metadata