mph-substack-publish
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes local Node.js (
render.mjs) and Python (create_draft_from_md.py) scripts located within the user's home directory and vendor-specific repositories. It also employs shell commands likefindandgit rev-parseto dynamically locate the deployment script on the host system. - [PROMPT_INJECTION]: Ingests user-supplied subjects to generate the body of the Substack post. The skill does not define explicit boundary markers to encapsulate this data, creating an indirect prompt injection surface where untrusted input could attempt to influence the agent's drafting instructions.
Audit Metadata