social-media-carousel
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
belt-sh/clitool and references installation documentation hosted on theinference-shGitHub repository. - [COMMAND_EXECUTION]: The skill instructs the agent to use the
beltCLI for executing remote applications such asinfsh/html-to-imageandfalai/flux-dev-lora, as well as performing batch generation of slides using bash loops. - [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface where untrusted data could be interpolated into HTML templates that are then rendered by remote tools.
- Ingestion points: Input strings used to populate carousel slide content (e.g., headlines, body text).
- Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present in the provided templates.
- Capability inventory: The skill utilizes the
beltCLI to perform remote application execution and image generation. - Sanitization: No evidence of sanitization or escaping of external content before interpolation into the HTML templates is provided.
Audit Metadata