substack-interviewer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions and template emphasize data integrity and local storage (~/.substack-skills/story-bank.md), ensuring user material is kept within the user's control and used only for its stated purpose.
- [NO_CODE]: The skill consists entirely of instructional markdown and reference files with no executable scripts, binaries, or automated code execution patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided data from a persistent local file to provide context for future writing tasks. The potential for malicious input to influence the agent is mitigated by a comprehensive anti-fabrication document (references/anti-fabrication.md) that serves as a boundary marker, strictly limiting the AI to the user's literal words and forbidding the invention of feelings, credentials, or demographics. The skill's capabilities are limited to reading and writing this specific local file, and it lacks the network or execution capabilities necessary for an injection to escalate into a significant security event.
Audit Metadata