social-media-carousel

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the belt-sh/cli tool and references installation documentation hosted on the inference-sh GitHub repository.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the belt CLI for executing remote applications such as infsh/html-to-image and falai/flux-dev-lora, as well as performing batch generation of slides using bash loops.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface where untrusted data could be interpolated into HTML templates that are then rendered by remote tools.
  • Ingestion points: Input strings used to populate carousel slide content (e.g., headlines, body text).
  • Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present in the provided templates.
  • Capability inventory: The skill utilizes the belt CLI to perform remote application execution and image generation.
  • Sanitization: No evidence of sanitization or escaping of external content before interpolation into the HTML templates is provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — social-media-carousel