blog-cluster

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill implements strict Cross-Site Scripting (XSS) protections for generated HTML artifacts (cluster-map.html). It explicitly forbids inline scripts, external script sources, and event handler attributes, relying solely on CSS for interactivity.\n- [COMMAND_EXECUTION]: Orchestration of sub-tasks (e.g., calling blog-write and blog-image) is performed using the Task tool. This is a legitimate use of the agent's capability to manage complex workflows.\n- [EXTERNAL_DOWNLOADS]: External data is retrieved via WebSearch for the purpose of keyword research and SERP analysis. This is a standard functional requirement for an SEO planning tool and does not involve execution of untrusted code.\n- [SAFE]: File system interactions are limited to reading/writing markdown, JSON, and HTML files within a dedicated project folder, ensuring no interference with system-level or sensitive files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 08:44 AM
Security Audit — agent-trust-hub — blog-cluster