substack-profile-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions are focused on text auditing and rewriting based on specific stylistic and factual constraints. It does not perform network operations, command execution, or sensitive data access beyond its own configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for untrusted data as it processes Substack profile pages which could potentially contain malicious instructions. However, the risk is mitigated by the skill's core logic and the strict rules in the referenced files.
  • Ingestion points: Substack 'About' pages, publication descriptions, and profile bios provided by the user for review.
  • Boundary markers: The skill does not use explicit boundary markers for inputs, but it is heavily constrained by the 'anti-fabrication' instructions.
  • Capability inventory: The skill is limited to reading specific local files (~/.substack-skills/) and generating text based on provided rules. It lacks high-risk capabilities like shell execution or network requests.
  • Sanitization: The 'references/anti-fabrication.md' file provides robust instructions that explicitly forbid the AI from inventing, inferring, or following 'typical' examples, effectively preventing the agent from acting on instructions embedded within the analyzed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:35 PM
Security Audit — agent-trust-hub — substack-profile-auditor