substack-analytics-digest
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data provided by the user, such as Substack statistics, dashboard numbers, and post performance exports.
- Ingestion points: User-supplied statistical data and performance export files referenced in
SKILL.md. - Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between the data and agent instructions.
- Capability inventory: The skill uses a code execution tool to perform arithmetic on user-provided files and references platform capabilities in
references/platform-limits.md. - Sanitization: There is no evidence of input validation or sanitization for the data being processed.
- [DYNAMIC_EXECUTION]: The skill explicitly instructs the agent to "Compute with code when a file is given" to ensure arithmetic accuracy. This pattern involves the runtime generation and execution of analysis scripts (e.g., Python or JavaScript) based on the structure and content of untrusted user files.
Audit Metadata