substack-content-planner

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes information from external files and user inputs, creating a potential vector for instructions embedded within that data to influence agent behavior.\n
  • Ingestion points: The skill retrieves content from local files located at ~/.substack-skills/voice-profile.md and ~/.substack-skills/story-bank.md, as well as from user-provided messages, to populate the content calendar.\n
  • Boundary markers: There are no specific delimiters or instructions provided to the agent to distinguish between the skill's core instructions and the content retrieved from external sources.\n
  • Capability inventory: The skill is designed to produce text-based planning output, such as markdown tables and cadence descriptions. It does not appear to have access to sensitive capabilities like network operations, file-writing, or shell command execution in the provided configuration.\n
  • Sanitization: No explicit methods for validating, filtering, or sanitizing the data ingested from the story bank or user messages are mentioned.\n- [EXTERNAL_DOWNLOADS]: The skill references documentation and templates hosted on external platforms.\n
  • Description: The reference files contain links to official Substack support documentation and an external GitHub repository (github.com/Solo-AI-Lab/substack-notes-skills) which provides the taxonomy for note formats used by the planner.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:35 PM
Security Audit — agent-trust-hub — substack-content-planner