technical-blog-writing

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires installing the 'belt' CLI from the 'belt-sh' organization and references setup scripts hosted on GitHub by 'inference-sh'.
  • [DYNAMIC_EXECUTION]: The skill includes examples that execute Python code for chart generation using the 'infsh/python-executor' service.
  • [INDIRECT_PROMPT_INJECTION]: By integrating with 'exa/search', the skill introduces a risk where untrusted search results containing malicious instructions could influence the agent. Ingestion point at 'exa/search' call; no boundary markers or sanitization logic specified; the agent has capabilities to post to external platforms like X via 'x/post-create'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:18 PM
Security Audit — agent-trust-hub — technical-blog-writing