post-publisher
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides explicit instructions for the agent to use
curlcommands to manage social media posts via the Typefully API. - [EXTERNAL_DOWNLOADS]: The skill interacts with external domains
api.typefully.comandcatbox.moe. These services are used for API communication and image hosting respectively. - [DATA_EXFILTRATION]: Content and images are uploaded to external services (
api.typefully.comandcatbox.moe). While this matches the skill's stated purpose of publishing content, it involves transmitting data to third-party infrastructure. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it processes data from external files:
- Ingestion points: The skill reads content from the
marketing/drafts/directory. - Boundary markers: The instructions lack specific delimiters or warnings to treat ingested draft content as untrusted data.
- Capability inventory: The agent can perform network requests (
curl) and local file writes (marketing/post-log.md) while processing this data. - Sanitization: There are no documented steps for validating or sanitizing the content of the drafts before they are used in API calls.
Audit Metadata