pre-publish-post-assistant

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external content, which presents a surface for indirect prompt injection attacks.
  • Ingestion points: The skill accepts content through three main vectors: local file paths (e.g., /path/to/draft.md), external web URLs, and raw text blocks provided by the user.
  • Boundary markers: The instructions do not define clear delimiters or specific instructions to the agent to ignore potentially malicious embedded commands within the processed drafts.
  • Capability inventory: The agent is empowered to read files from the local filesystem, fetch content from remote URLs, and query external GraphQL endpoints.
  • Sanitization: There is no description of content sanitization, filtering, or validation performed on the ingested data before it is processed by the language model.
  • [COMMAND_EXECUTION]: The skill instructions involve interacting with the local environment to fetch taxonomy data.
  • Evidence: The configuration mentions parsing a static /dist folder for built site pages and reading from a local taxonomy.json file to determine post distribution counts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:03 AM
Security Audit — agent-trust-hub — pre-publish-post-assistant