newsletter-curation

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the 'belt-sh/cli' tool and references external setup documentation hosted on GitHub at https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md.
  • [COMMAND_EXECUTION]: The skill uses the 'belt' CLI to run several applications for searching, image generation, and social media posting.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface. 1. Ingestion points: search results from 'tavily/search-assistant' and 'exa/search' tools. 2. Boundary markers: No markers are used to separate ingested data from agent instructions. 3. Capability inventory: Ability to post to social media via 'x/post-create'. 4. Sanitization: No sanitization of ingested content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:32 PM
Security Audit — agent-trust-hub — newsletter-curation