a1-editor-in-chief
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill manages the risk of indirect prompt injection by implementing a structured editorial diagnosis and review process.\n
- Ingestion points: User-provided
Inputtext.\n - Boundary markers: A structured internal
Copy Editing Briefwith explicit "Allowed" and "Forbidden" moves.\n - Capability inventory: Task delegation to a sibling skill; no direct execution of shell commands or external network writing of input.\n
- Sanitization: A precedence-based resolution protocol (source-resolution.md) that protects canonical product facts and prohibitions from being overridden by untrusted input.\n- [SAFE]: Context Isolation. The skill prevents cross-project data leakage by restricting context discovery to the active repository and explicitly forbidding access to global profiles or previous project sentinels.\n- [SAFE]: Scope Control. A dedicated scope classification stage ensures the agent refuses tasks outside its editorial mandate, such as marketing strategy or pricing calculations.\n- [SAFE]: Dependency Validation. The agent verifies the existence of sibling skills on the local filesystem before initiating workflows, preventing unsafe fallbacks.\n- [SAFE]: Information Reference. The skill provides a support link to a well-known communication platform (Telegram) for user feedback.
Audit Metadata