content-publish

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses an inline Node.js script (node -e) to dynamically process MDX content and generate JSON payloads at runtime. This script performs file system operations (reading source files and writing to /tmp) and string manipulation to prepare data for the database.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingest and processes external MDX files, creating a potential surface for instructions hidden in data to influence agent behavior.
  • Ingestion points: MDX content is read from local file paths (e.g., ~/Code/joelhooks/joelclaw/apps/web) provided by the user or identified by the agent.
  • Boundary markers: No explicit delimiters or instructions are used to signal that the agent should ignore instructions embedded within the processed content.
  • Capability inventory: The skill possesses shell execution capabilities (npx convex) and network access (curl), which are accessible during the content processing lifecycle.
  • Sanitization: Processing is limited to frontmatter removal and does not include filtering for potentially malicious natural language instructions.
  • [COMMAND_EXECUTION]: The skill executes shell commands using npx convex for database interactions and curl for triggering site revalidation and verifying deployment status.
  • [EXTERNAL_DOWNLOADS]: The skill uses the npx command, which may download and execute the convex CLI package from the public registry if it is not locally available.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — content-publish