a1-editor-in-chief

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill manages the risk of indirect prompt injection by implementing a structured editorial diagnosis and review process.\n
  • Ingestion points: User-provided Input text.\n
  • Boundary markers: A structured internal Copy Editing Brief with explicit "Allowed" and "Forbidden" moves.\n
  • Capability inventory: Task delegation to a sibling skill; no direct execution of shell commands or external network writing of input.\n
  • Sanitization: A precedence-based resolution protocol (source-resolution.md) that protects canonical product facts and prohibitions from being overridden by untrusted input.\n- [SAFE]: Context Isolation. The skill prevents cross-project data leakage by restricting context discovery to the active repository and explicitly forbidding access to global profiles or previous project sentinels.\n- [SAFE]: Scope Control. A dedicated scope classification stage ensures the agent refuses tasks outside its editorial mandate, such as marketing strategy or pricing calculations.\n- [SAFE]: Dependency Validation. The agent verifies the existence of sibling skills on the local filesystem before initiating workflows, preventing unsafe fallbacks.\n- [SAFE]: Information Reference. The skill provides a support link to a well-known communication platform (Telegram) for user feedback.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 06:33 AM
Security Audit — agent-trust-hub — a1-editor-in-chief