content-publisher

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted content from the web to generate articles, creating an indirect prompt injection surface. Ingestion points: The pseudo-code in SKILL.md calls the apify/firecrawl-scraper on external URLs. Boundary markers: None are specified to separate scraped content from system instructions. Capability inventory: The skill has access to file system writes, browser automation tools, and Slack notifications. Sanitization: No validation or filtering of scraped data is described.
  • [CREDENTIALS_UNSAFE]: The memory/credentials-template.md file encourages storing plain-text passwords in the agent's memory folder. This pattern creates a high-impact risk of credential exposure if the agent is manipulated by untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 11:21 PM
Security Audit — agent-trust-hub — content-publisher