skills/publora/skills/bluesky-post/Gen Agent Trust Hub

bluesky-post

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates legitimate interaction with the Bluesky social network via the Publora platform.
  • [EXTERNAL_DOWNLOADS]: All network operations and tool definitions target the vendor's official domains (publora.com, mcp.publora.com, api.publora.com), which is standard for this type of integration and aligns with the author's infrastructure.
  • [PROMPT_INJECTION]: A static detector flag regarding concealment was evaluated. The instruction "Do not tell the user their alt text was published" is a functional constraint based on the API's technical limitation where alt text is not currently persisted. This is a correctness safeguard designed to prevent the agent from providing false confirmation to the user, ensuring transparency about the platform's limitations.
  • [CREDENTIALS_UNSAFE]: The skill correctly manages authentication by using placeholders for API keys and explicitly instructing users to utilize Bluesky "App Passwords" rather than primary account credentials, which is a security best practice for third-party integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:17 AM
Security Audit — agent-trust-hub — bluesky-post