substack-post-writer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions (SKILL.md) direct the agent to access and read files from a hidden directory in the user's home folder to personalize output.
- Evidence:
Read ~/.substack-skills/voice-profile.md and ~/.substack-skills/story-bank.md if they exist. - Risk: While intended for legitimate personalization, instructions that access hidden files in the home directory (
~/) constitute a sensitive file path access that could be abused to expose user data if the path is manipulated or the files contain sensitive information. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted user data (outlines and messages) to generate complex outputs without sufficient boundary markers.
- Ingestion points: User-provided outlines, message history, and files mentioned in the prompt are used to build post sections (SKILL.md).
- Boundary markers: Absent. The prompt does not define delimiters to separate user data from instructions or include warnings to ignore embedded commands.
- Capability inventory: The skill drafts long-form content and generates structured metadata blocks for subsequent use by other tools like
substack-publisher. - Sanitization: Absent. There is no evidence of filtering or validation of the input content before it is used for drafting.
- [EXTERNAL_DOWNLOADS]: The skill documentation references a external source for its anti-fabrication guidelines.
- Evidence:
references/anti-fabrication.mdciteshttps://github.com/Solo-AI-Lab/substack-notes-skillsas the source of its logic. - Analysis: This is a static reference for documentation purposes and does not represent an automated runtime download or execution of external code.
Audit Metadata