post-publisher

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides explicit instructions for the agent to use curl commands to manage social media posts via the Typefully API.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with external domains api.typefully.com and catbox.moe. These services are used for API communication and image hosting respectively.
  • [DATA_EXFILTRATION]: Content and images are uploaded to external services (api.typefully.com and catbox.moe). While this matches the skill's stated purpose of publishing content, it involves transmitting data to third-party infrastructure.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it processes data from external files:
  • Ingestion points: The skill reads content from the marketing/drafts/ directory.
  • Boundary markers: The instructions lack specific delimiters or warnings to treat ingested draft content as untrusted data.
  • Capability inventory: The agent can perform network requests (curl) and local file writes (marketing/post-log.md) while processing this data.
  • Sanitization: There are no documented steps for validating or sanitizing the content of the drafts before they are used in API calls.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — post-publisher