writing-clone-starter
Fail
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The file
references/built-in-profiles/zhouzuoluo/raw-corpus/README.mdlistshttps://wxredian.com/art?id=07bf527cfa52a366210c61375cc30b6fas a source of material. This URL has been flagged as a phishing site by security scanners, and the file containing it has been identified as suspicious by AV software. - [DATA_EXFILTRATION]: The skill architecture (e.g., in
references/profile-distillation/material-sync.md) encourages the agent to use tools likeweb-clipperto fetch content from third-party mirrors and URLs. This creates a data pipeline where sensitive information could be exposed to untrusted external sites or included in local library files without proper isolation. - [PROMPT_INJECTION]: The skill instructs the agent to process and analyze large quantities of external, untrusted text (clippings, raw corpus material). There are no defined security boundaries or sanitization steps to prevent indirect prompt injection, where malicious instructions hidden in writing samples could manipulate the agent's behavior.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata