novel-proofreader
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided manuscripts, creating a potential attack surface for instructions hidden within fiction text.
- Ingestion points: Manuscript files (text, Markdown) are read into the agent context as described in the processing steps of SKILL.md.
- Boundary markers: The skill does not define specific delimiters or explicit instructions to ignore embedded commands within the manuscript content.
- Capability inventory: The skill utilizes Write and Edit tools to generate and modify files on the local disk (.typeset and .proofread.md).
- Sanitization: There is no evidence of automated sanitization or filtering performed on the manuscript content prior to analysis and modification.
Audit Metadata