blog-strategy

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external websites, creating a surface for indirect prompt injection.
  • Ingestion points: Competitor blog content and AI platform citation data are retrieved via WebSearch and WebFetch tools in Step 2.
  • Boundary markers: The instructions lack explicit delimiters or specific directives to ignore embedded instructions found in the analyzed external web pages.
  • Capability inventory: The skill environment includes potentially sensitive tools such as Bash, Write, and Task.
  • Sanitization: There are no documented steps for sanitizing or validating external content before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill uses WebSearch and WebFetch to access and retrieve data from competitor domains and AI search platforms as part of its core research workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:44 AM