technical-blog-writing
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
belt-sh/clivia npx and references external documentation hosted on GitHub. - [DYNAMIC_EXECUTION]: The skill uses the
infsh/python-executortool to execute Python code for generating charts, representing a capability for dynamic code execution within the agent environment. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its use of external search results. Ingestion points: Search results from
exa/searchare incorporated into the agent context. Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the untrusted search data. Capability inventory: The skill has access to network operations (x/post-create), shell commands (Bash(belt *)), and Python code execution (infsh/python-executor). Sanitization: There is no evidence of sanitization or validation of the external content before it is processed.
Audit Metadata