content-tone-adjuster
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user-provided text for rewriting, which is an inherent surface for indirect prompt injection. ● Ingestion points: User-provided text or documents for style adjustment as defined in SKILL.md. ● Boundary markers: No delimiters or explicit instructions are provided to help the agent distinguish user data from embedded instructions. ● Capability inventory: The skill has access to file reading, file editing, and network search tools. ● Sanitization: No content validation or filtering is applied to the input text.
- [EXTERNAL_DOWNLOADS]: The skill uses network search functionality to support its specific task of identifying AI-generated writing patterns. ● Evidence: The 'remove-ai-artifacts' prompt instructs the agent to 'execute once network search' to find current model stereotypical expressions. This is a legitimate functional requirement for the style adjustment task.
Audit Metadata