newsletter-curation
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
beltCLI via the commandnpx skills add belt-sh/cliand provides a link to installation instructions athttps://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md. These resources are consistent with the skill's stated purpose of providing a curation workflow for the inference.sh platform.\n- [INDIRECT_PROMPT_INJECTION]: The skill acts as a curation engine that ingests and processes untrusted data from external sources.\n - Ingestion points: Data enters the agent's context through the outputs of the
tavily/search-assistantandexa/searchapps via thebelt app runcommand.\n - Boundary markers: No explicit delimiters or 'ignore embedded instructions' warnings are provided for the interpolation of search results into the curation workflow.\n
- Capability inventory: The skill possesses restricted shell access (limited specifically to the
beltcommand via theBash(belt *)frontmatter) and the ability to format and generate content for output.\n - Sanitization: The instructions do not define specific validation or filtering steps for the ingested web content, relying on the agent's editorial judgment.
Audit Metadata