substack-post-writer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions (SKILL.md) direct the agent to access and read files from a hidden directory in the user's home folder to personalize output.
  • Evidence: Read ~/.substack-skills/voice-profile.md and ~/.substack-skills/story-bank.md if they exist.
  • Risk: While intended for legitimate personalization, instructions that access hidden files in the home directory (~/) constitute a sensitive file path access that could be abused to expose user data if the path is manipulated or the files contain sensitive information.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted user data (outlines and messages) to generate complex outputs without sufficient boundary markers.
  • Ingestion points: User-provided outlines, message history, and files mentioned in the prompt are used to build post sections (SKILL.md).
  • Boundary markers: Absent. The prompt does not define delimiters to separate user data from instructions or include warnings to ignore embedded commands.
  • Capability inventory: The skill drafts long-form content and generates structured metadata blocks for subsequent use by other tools like substack-publisher.
  • Sanitization: Absent. There is no evidence of filtering or validation of the input content before it is used for drafting.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references a external source for its anti-fabrication guidelines.
  • Evidence: references/anti-fabrication.md cites https://github.com/Solo-AI-Lab/substack-notes-skills as the source of its logic.
  • Analysis: This is a static reference for documentation purposes and does not represent an automated runtime download or execution of external code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:35 PM
Security Audit — agent-trust-hub — substack-post-writer