case-study-writing
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves installation details and tools from GitHub and the NPM registry to configure the belt CLI environment.
- [REMOTE_CODE_EXECUTION]: It uses the npx command to execute the skills package which manages plugin installations.
- [COMMAND_EXECUTION]: The skill contains instructions to execute Python scripts for generating charts via the infsh/python-executor tool.
- [PROMPT_INJECTION]: The skill ingests untrusted data from the web using Tavily and Exa search tools without explicit boundary markers or sanitization, creating an indirect injection surface while using the python-executor capability.
Audit Metadata