duplicator

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill describes a workflow that ingests data from external websites and uses it to generate content for social media, creating a surface for indirect prompt injection. Ingestion points: Website content scanned as part of the 'Capture the source' procedure in SKILL.md. Boundary markers: No delimiters or safety instructions for handling scanned content are specified in the provided instructions. Capability inventory: The skill utilizes the agent's capability to post generated content to external APIs (Facebook, Dev.to, GitHub, etc.) via API keys. Sanitization: No sanitization or validation of the ingested site content is mentioned.
  • [DATA_EXFILTRATION]: The skill requires the agent to handle and use sensitive API keys for multiple external platforms. While the documentation warns against committing keys to version control, the operational requirement for the agent to manage these secrets during network operations presents a risk of accidental exposure or exfiltration.
  • [EXTERNAL_DOWNLOADS]: The README provides installation instructions using the command 'npx skills add axelfreeman/duplicator', which fetches resources from an external registry. This is documented as a vendor-specific resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 01:48 PM
Security Audit — agent-trust-hub — duplicator