technical-blog-writing
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires installing the 'belt' CLI from the 'belt-sh' organization and references setup scripts hosted on GitHub by 'inference-sh'.
- [DYNAMIC_EXECUTION]: The skill includes examples that execute Python code for chart generation using the 'infsh/python-executor' service.
- [INDIRECT_PROMPT_INJECTION]: By integrating with 'exa/search', the skill introduces a risk where untrusted search results containing malicious instructions could influence the agent. Ingestion point at 'exa/search' call; no boundary markers or sanitization logic specified; the agent has capabilities to post to external platforms like X via 'x/post-create'.
Audit Metadata