substack-segment-campaigns

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted external data, creating a potential surface for indirect prompt injection.
  • Ingestion points: Subscriber exports (CSV) and pasted text from other writers (notes, comments) as defined in SKILL.md and references/untrusted-content.md.
  • Boundary markers: The skill includes a dedicated security file, references/untrusted-content.md, which explicitly instructs the agent to treat external text as data and never as instructions.
  • Capability inventory: The skill is primarily focused on text generation and data analysis; it does not contain code execution or automated network operations in the provided files.
  • Sanitization: The instructions include strict guardrails to identify and ignore text aimed at influencing AI behavior.
  • [DATA_EXFILTRATION]: While the skill processes sensitive PII from subscriber exports, it implements robust privacy controls.
  • Evidence: references/untrusted-content.md section 2 strictly prohibits the output of individual names or email addresses, mandating that the agent only provide aggregate data like counts and date ranges.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:34 PM
Security Audit — agent-trust-hub — substack-segment-campaigns