bestblogs-explain

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the bestblogs CLI tool to retrieve analytics and profile data. It passes parameters like <id> and --days to the shell environment.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes content from the bestblogs CLI output.
  • Ingestion points: Data enters the context via CLI output fields such as sourceName, selectionReason, and implicitInterests (SKILL.md).
  • Boundary markers: None identified; output is interpolated directly into the response.
  • Capability inventory: Command execution via the bestblogs CLI (SKILL.md).
  • Sanitization: No evidence of validation for the CLI results before presentation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 07:31 AM
Security Audit — agent-trust-hub — bestblogs-explain