attribute-performance
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external web sources which could contain malicious instructions.
- Ingestion points: Fetches Substack post content and social mentions via the WebFetch tool in SKILL.md.
- Boundary markers: No delimiters or instructions to ignore embedded commands are present in the workflow.
- Capability inventory: No dangerous system capabilities such as shell execution, file system modification, or credential access were identified.
- Sanitization: No validation or sanitization of the fetched external content is described.
Audit Metadata