linkedin-content

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external installation guide and encourages the addition of external skills from the belt-sh and inference-sh organizations to the agent's environment.
  • [COMMAND_EXECUTION]: The skill utilizes the belt CLI tool (authorized via allowed-tools) to perform tasks such as content research and cross-platform social media posting.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow that processes untrusted data from external sources, which could potentially contain malicious instructions.
  • Ingestion points: Web search results retrieved via the tavily/search-assistant app within the belt CLI (referenced in SKILL.md).
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' instructions when processing search output.
  • Capability inventory: The skill has the capability to write to external platforms via the x/post-create command.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the content retrieved from search results before using it to generate social media posts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:18 PM
Security Audit — agent-trust-hub — linkedin-content