substack-segment-campaigns
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted external data, creating a potential surface for indirect prompt injection.
- Ingestion points: Subscriber exports (CSV) and pasted text from other writers (notes, comments) as defined in
SKILL.mdandreferences/untrusted-content.md. - Boundary markers: The skill includes a dedicated security file,
references/untrusted-content.md, which explicitly instructs the agent to treat external text as data and never as instructions. - Capability inventory: The skill is primarily focused on text generation and data analysis; it does not contain code execution or automated network operations in the provided files.
- Sanitization: The instructions include strict guardrails to identify and ignore text aimed at influencing AI behavior.
- [DATA_EXFILTRATION]: While the skill processes sensitive PII from subscriber exports, it implements robust privacy controls.
- Evidence:
references/untrusted-content.mdsection 2 strictly prohibits the output of individual names or email addresses, mandating that the agent only provide aggregate data like counts and date ranges.
Audit Metadata