post-writer-sms
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from a local file to define its writing parameters.\n
- Ingestion points: The skill reads the file
.agents/social-media-context-sms.mdto adopt the user's voice, tone, and preferences (File: SKILL.md).\n - Boundary markers: There are no boundary markers or instructions to the agent to ignore potentially malicious embedded instructions within the context file.\n
- Capability inventory: The skill is capable of external network operations via the
create_posttool provided by the BlackTwist MCP (File: SKILL.md).\n - Sanitization: The skill does not perform any validation, sanitization, or filtering of the content retrieved from the context file before incorporating it into its prompt logic.
Audit Metadata