newsletter-curation
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the 'belt' CLI and related skill modules from the 'inference-sh' GitHub repository. These resources are part of the platform's standard ecosystem.
- [COMMAND_EXECUTION]: Instructions involve using the 'belt' CLI to execute various sub-applications for content search (Tavily, Exa), social media creation, and HTML image generation. The use of these tools is limited to the 'belt' executable scope.
- [PROMPT_INJECTION]: The skill is designed to ingest and summarize data from external search providers, which constitutes a surface for indirect prompt injection. * Ingestion points: Web content and search results from the Tavily and Exa assistant tools. * Boundary markers: The provided templates do not include clear delimiters or instructions to ignore embedded commands within the fetched content. * Capability inventory: The skill has the capability to run shell commands via the 'belt' CLI. * Sanitization: The instructions do not specify any validation or sanitization for the external data being processed.
Audit Metadata