substack-publisher

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a Python script (scripts/publish.py) to interact with the Substack API. This is the intended primary purpose of the skill. The instructions emphasize that these commands should only be run after explicit user approval of the content to be published.
  • [CREDENTIALS_SAFE]: The skill uses a .env file located in a dedicated user directory (~/.substack-skills/.env) to store Substack session cookies. This follows security best practices by keeping sensitive data out of the skill's source directory and chat history. The script even includes a redact function to scrub session tokens from any error messages or output before they are displayed.
  • [DATA_EXPOSURE]: There is a risk of exposing the session cookie if the user accidentally pastes it into the chat. However, the skill specifically instructs the agent not to use or record the cookie if provided in the chat and guides the user on the correct, safe way to provide it via the local .env file.
  • [EXTERNAL_DOWNLOADS]: The skill mentions that the user may need to install the python-substack package via pip. As this is a well-known public package registry, this is considered safe.
  • [SAFE]: The skill includes 'Hard rules' that strictly prohibit automated or scheduled publishing without a user present, aligning both with security best practices and Substack's Terms of Service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:34 PM
Security Audit — agent-trust-hub — substack-publisher