substack-notes-writer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content which creates a vulnerability to indirect prompt injection attacks where instructions could be embedded in data.
  • Ingestion points: In references/untrusted-content.md, the skill identifies "pasted Notes, comments, transcripts, other writers' posts, and file contents" as potential sources of malicious text intended to manipulate the AI.
  • Boundary markers: The skill includes explicit defensive instructions to treat external text solely as data and never as instructions. It also mandates notifying the user if text aimed at an AI is detected.
  • Capability inventory: The skill is capable of drafting content for social feeds and provides instructions for passing approved text to a publishing tool (substack-publisher), creating a path from processed data to public output.
  • Sanitization: The instructions specifically forbid the AI from allowing external content to trigger publishing actions, add unauthorized links, or influence drafts in ways not explicitly approved by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:35 PM
Security Audit — agent-trust-hub — substack-notes-writer