post-writer-sms

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from a local file to define its writing parameters.\n
  • Ingestion points: The skill reads the file .agents/social-media-context-sms.md to adopt the user's voice, tone, and preferences (File: SKILL.md).\n
  • Boundary markers: There are no boundary markers or instructions to the agent to ignore potentially malicious embedded instructions within the context file.\n
  • Capability inventory: The skill is capable of external network operations via the create_post tool provided by the BlackTwist MCP (File: SKILL.md).\n
  • Sanitization: The skill does not perform any validation, sanitization, or filtering of the content retrieved from the context file before incorporating it into its prompt logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 10:54 PM