newsletter-curation

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the belt CLI via the command npx skills add belt-sh/cli and provides a link to installation instructions at https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md. These resources are consistent with the skill's stated purpose of providing a curation workflow for the inference.sh platform.\n- [INDIRECT_PROMPT_INJECTION]: The skill acts as a curation engine that ingests and processes untrusted data from external sources.\n
  • Ingestion points: Data enters the agent's context through the outputs of the tavily/search-assistant and exa/search apps via the belt app run command.\n
  • Boundary markers: No explicit delimiters or 'ignore embedded instructions' warnings are provided for the interpolation of search results into the curation workflow.\n
  • Capability inventory: The skill possesses restricted shell access (limited specifically to the belt command via the Bash(belt *) frontmatter) and the ability to format and generate content for output.\n
  • Sanitization: The instructions do not define specific validation or filtering steps for the ingested web content, relying on the agent's editorial judgment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — newsletter-curation