social-post
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill connects to the vendor's own infrastructure at
mcp.publora.comandapi.publora.comto perform its primary functions. These are expected communications for a service-integrated skill. - [COMMAND_EXECUTION]: The documentation includes standard setup commands for the Claude Code CLI (
claude mcp add) to configure the Model Context Protocol (MCP) server. These commands are informational and use safe placeholders for authentication tokens. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as the
create_posttool accepts arbitrary user-supplied text in thecontentparameter and processes externalmediaUrls. However, this behavior is central to the skill's purpose of social media management, and the server-side validation described in the documentation provides a layer of protection against malformed inputs.
Audit Metadata