email-design

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the belt-sh/cli tool and references external setup documentation hosted on a third-party GitHub repository (inference-sh/skills).- [COMMAND_EXECUTION]: Employs the Bash tool to run belt commands for account login and application execution. The tool usage is constrained to the belt binary via the YAML frontmatter.- [INDIRECT_PROMPT_INJECTION]: The skill defines templates that pass user-supplied HTML content into CLI arguments for image generation tools without explicit sanitization.
  • Ingestion points: HTML strings within the --input argument of belt app run commands.
  • Boundary markers: Absent; uses standard shell argument quoting.
  • Capability inventory: Invocation of external AI models via the belt CLI and Bash tool.
  • Sanitization: Absent; the skill does not suggest or implement escaping for the interpolated HTML.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:10 PM
Security Audit — agent-trust-hub — email-design