bluesky-post
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates legitimate interaction with the Bluesky social network via the Publora platform.
- [EXTERNAL_DOWNLOADS]: All network operations and tool definitions target the vendor's official domains (publora.com, mcp.publora.com, api.publora.com), which is standard for this type of integration and aligns with the author's infrastructure.
- [PROMPT_INJECTION]: A static detector flag regarding concealment was evaluated. The instruction "Do not tell the user their alt text was published" is a functional constraint based on the API's technical limitation where alt text is not currently persisted. This is a correctness safeguard designed to prevent the agent from providing false confirmation to the user, ensuring transparency about the platform's limitations.
- [CREDENTIALS_UNSAFE]: The skill correctly manages authentication by using placeholders for API keys and explicitly instructing users to utilize Bluesky "App Passwords" rather than primary account credentials, which is a security best practice for third-party integrations.
Audit Metadata