press-release-writing

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external installation script and documentation hosted at https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md.
  • [REMOTE_CODE_EXECUTION]: The instructions prompt the user to install and execute external code packages from repositories such as belt-sh/cli and inference-sh/skills using the npx skills add command. These are non-standard sources for code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external search assistants (Tavily and Exa) via the belt CLI tool.
  • Ingestion points: Data returned from belt app run for research and fact-checking purposes in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore potential malicious prompts embedded within search results.
  • Capability inventory: The skill has access to shell execution via the Bash(belt *) tool specified in the allowed-tools frontmatter.
  • Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external search providers before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — press-release-writing