case-study-writing

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the belt-sh/cli package and references installation documentation hosted on the official inference-sh GitHub repository.
  • [COMMAND_EXECUTION]: Uses the belt CLI for authenticated login and to run utility apps for industry research, such as tavily/search-assistant and exa/search.
  • [REMOTE_CODE_EXECUTION]: Provides a template for generating before/after comparison charts using the infsh/python-executor tool. The provided Python script uses matplotlib and is designed for static data visualization based on the case study metrics.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it ingests data from external search tools while possessing code execution capabilities.
  • Ingestion points: External data enters the context via tavily/search-assistant and exa/search tool outputs as instructed in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are included for the agent when processing search results.
  • Capability inventory: The skill has access to the Bash(belt *) toolset and the infsh/python-executor environment.
  • Sanitization: There is no evidence of sanitization or validation of the external content retrieved from the search tools before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:04 PM
Security Audit — agent-trust-hub — case-study-writing