writing-shape
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and processing external raw material from files, which constitutes a vulnerability surface for indirect instructions. 1. Ingestion points: The skill reads an input file (the 'pile') as specified in SKILL.md. 2. Boundary markers: There are no explicit delimiters or safety instructions provided to the agent to distinguish between the input data and potentially embedded malicious instructions. 3. Capability inventory: The skill has the capability to read from and write to the local file system. 4. Sanitization: The instructions do not define any sanitization or validation protocols for the external content. Note: As this processing is the intended primary purpose of the skill, the associated risk is considered safe for the defined use case.
Audit Metadata