technical-blog-writing

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the belt-sh/cli via npx and references external documentation hosted on GitHub.
  • [DYNAMIC_EXECUTION]: The skill uses the infsh/python-executor tool to execute Python code for generating charts, representing a capability for dynamic code execution within the agent environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its use of external search results. Ingestion points: Search results from exa/search are incorporated into the agent context. Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the untrusted search data. Capability inventory: The skill has access to network operations (x/post-create), shell commands (Bash(belt *)), and Python code execution (infsh/python-executor). Sanitization: There is no evidence of sanitization or validation of the external content before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:15 PM
Security Audit — agent-trust-hub — technical-blog-writing