substack-publisher
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Python script (
scripts/publish.py) to interact with the Substack API. This is the intended primary purpose of the skill. The instructions emphasize that these commands should only be run after explicit user approval of the content to be published. - [CREDENTIALS_SAFE]: The skill uses a
.envfile located in a dedicated user directory (~/.substack-skills/.env) to store Substack session cookies. This follows security best practices by keeping sensitive data out of the skill's source directory and chat history. The script even includes aredactfunction to scrub session tokens from any error messages or output before they are displayed. - [DATA_EXPOSURE]: There is a risk of exposing the session cookie if the user accidentally pastes it into the chat. However, the skill specifically instructs the agent not to use or record the cookie if provided in the chat and guides the user on the correct, safe way to provide it via the local
.envfile. - [EXTERNAL_DOWNLOADS]: The skill mentions that the user may need to install the
python-substackpackage viapip. As this is a well-known public package registry, this is considered safe. - [SAFE]: The skill includes 'Hard rules' that strictly prohibit automated or scheduled publishing without a user present, aligning both with security best practices and Substack's Terms of Service.
Audit Metadata