linkedin-content

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download installation guides from a public GitHub repository (github.com/inference-sh/skills), which is a well-known and trusted service for hosting documentation and code.
  • [COMMAND_EXECUTION]: The skill uses the belt CLI to perform authenticated actions (belt login) and run various applications for research and content creation, such as Tavily for search and X for cross-posting. These are legitimate functions for a social media management skill.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by consuming external data from search results to inform content creation. While this allows for potential influence from untrusted external sources, it is a standard behavior for search-augmented agents.
  • Ingestion points: External data enters the context through tavily/search-assistant results (SKILL.md).
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the provided templates.
  • Capability inventory: The skill possesses the capability to post to external social media platforms (x/post-create) and generate images.
  • Sanitization: No specific sanitization or validation steps are defined for the data retrieved from external search results.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 10:27 PM
Security Audit — agent-trust-hub — linkedin-content