writing-blog-posts
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is configured to use the
WebFetchtool to access external developer blogs and official documentation for style inspiration. The referenced sources, including MDN Web Docs, React Docs, and WordPress Developer News, are well-known and reputable technology services. These references align with the skill's purpose of drafting technical blog posts. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it ingests data from external websites via the
WebFetchtool. Instructions hidden within fetched pages could potentially attempt to override agent behavior. However, the risk is minimal as the skill does not have permissions for command execution or file system modifications, and the instructions focus on extracting style patterns rather than executing logic.
Audit Metadata