newsletter-curation
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references setup documentation and additional skill modules from the official inference-sh GitHub organization.
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run platform-specific commands for content searching via Tavily and Exa, image creation, and social media posting.
- [PROMPT_INJECTION]: The skill processes live data from external sources (Tavily and Exa search results in SKILL.md) which constitutes an indirect prompt injection surface. The absence of specific boundary markers or sanitization means the agent relies on its internal safety filters when processing this untrusted external data.
Audit Metadata