voice-reviewer

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's functionality is entirely instruction-based and does not include any shell commands, scripts, or network operations.
  • [PROMPT_INJECTION]: The skill processes untrusted data from project files (guidelines and content), which is a surface for indirect prompt injection. However, no dangerous capabilities are exposed to be exploited. 1. Ingestion points: Reads local markdown files and brand voice documentation. 2. Boundary markers: None are defined in the instructions to separate external data from agent instructions. 3. Capability inventory: No capabilities such as file-write, network access, or subprocess execution are defined. 4. Sanitization: No steps for sanitizing or escaping the content read from files are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 02:46 AM