verify-content-review

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from documents, articles, and presentation decks to perform editorial reviews and fact-checking. This creates a surface for indirect prompt injection because the instructions lack explicit boundary markers or delimiters to isolate the ingested content from the system logic, potentially allowing malicious content within the analyzed files to override agent behavior.
  • Ingestion points: SKILL.md (Step 1 references reading the artifact_type, content file path, and source materials).
  • Boundary markers: Absent. The instructions do not define unique tags or wrappers for external content.
  • Capability inventory: The skill directs the agent to make delivery decisions (triggering ship-artifact-export or build-content-writing), which are actions that could be manipulated via adversarial content.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:47 AM
Security Audit — agent-trust-hub — verify-content-review