skills/publora/skills/threads-post/Gen Agent Trust Hub

threads-post

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to the official Publora MCP server (mcp.publora.com) and REST API (api.publora.com) to perform its functions. These resources are owned by the skill's vendor and represent the intended operational environment for this integration.\n- [INDIRECT_PROMPT_INJECTION]: The skill includes a mediaUrls parameter in the create_post tool, which allows the ingestion of media from external public HTTPS URLs.\n
  • Ingestion points: The mediaUrls array parameter in the create_post tool (SKILL.md).\n
  • Boundary markers: No specific boundary markers are defined for the remote media content, though ingestion is limited to specific file formats.\n
  • Capability inventory: The skill performs network requests to the Publora platform and allows the platform to fetch remote media assets for processing.\n
  • Sanitization: The documentation indicates that the backend service performs server-side validation, format probing, and size checks (e.g., images < 8 MB) before publication.\n- [COMMAND_EXECUTION]: The documentation provides a setup command using the claude CLI to add the Publora MCP server. This is a standard administrative task for enabling the skill's functionality and requires the user to manually provide their own API key.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:17 AM
Security Audit — agent-trust-hub — threads-post