email-design
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
beltCLI tool to run remote HTML-to-image and AI image generation applications.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of thebelt-sh/cliNode.js package and references installation scripts from theinference-shGitHub repository.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data for email design and visual generation prompts.\n - Ingestion points: User input for subject lines, body copy, and image prompts in
SKILL.md.\n - Boundary markers: No delimiters or defensive instructions are present to prevent the agent from executing instructions embedded in user-provided content.\n
- Capability inventory: The skill uses
Bash(belt *)to interface with remote inference services.\n - Sanitization: No input validation or escaping logic is provided for external data.
Audit Metadata