case-study-writing
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from external web sources through search tools (tavily/search-assistant, exa/search). Evidence: SKILL.md. No explicit boundary markers or sanitization logic is provided to isolate external content from agent instructions. Capabilities available include full access to the infsh CLI and Python script execution.
- [COMMAND_EXECUTION]: Utilizes the infsh CLI to run specialized research and utility applications as part of the content creation workflow.
- [REMOTE_CODE_EXECUTION]: Generates and executes a Python script via the infsh/python-executor tool to produce visual charts from data metrics.
- [EXTERNAL_DOWNLOADS]: References installation scripts and additional skill dependencies hosted on the inference-sh GitHub repository and related vendor domains.
Audit Metadata