case-study-writing

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the 'belt-sh/cli' tool via npx and references external installation documentation hosted on a GitHub repository ('inference-sh/skills').
  • [COMMAND_EXECUTION]: The skill uses the 'belt' CLI tool to perform authentication and run various applications, which involves communication with external infrastructure.
  • [DYNAMIC_EXECUTION]: The skill demonstrates the use of 'infsh/python-executor' to execute Python code provided within the markdown for generating charts.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches content from external search engines, which could contain malicious instructions meant to influence the agent's behavior. 1. Ingestion points: Search results from 'tavily/search-assistant' and 'exa/search' are processed by the skill (SKILL.md). 2. Boundary markers: No clear delimiters or instructions to ignore embedded commands are present in the search workflow. 3. Capability inventory: The skill has access to the 'belt' CLI tool and a Python code executor. 4. Sanitization: No sanitization or validation logic is specified for the data retrieved from external research tools.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 05:55 PM
Security Audit — agent-trust-hub — case-study-writing