@1892/agent-blog

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools to fetch content from external URLs (scripts/import_article.py) and process external data feeds (scripts/import_x_articles.py) to generate blog posts. This represents an indirect prompt injection surface where a malicious external source could provide instructions designed to influence the agent's behavior when it later processes or summarizes the imported drafts.
  • Ingestion points: The URL argument in scripts/import_article.py and the JSON data source in scripts/import_x_articles.py.
  • Boundary markers: No explicit delimiters or warnings to ignore instructions within the imported content were identified.
  • Capability inventory: The skill can perform network reads (proxied_get, urllib.request.urlopen) and file writes across several scripts.
  • Sanitization: While the importer scopes CSS to prevent style leakage, it extracts and preserves inline script blocks and HTML text from the source without sanitizing them for prompt injection patterns.
  • [DYNAMIC_EXECUTION]: The generator (build.py) and the image generator (scripts/og_image.py) use importlib.util to dynamically load the config.py file from the project root. While this is a common pattern for local configuration in this type of project, dynamic loading from computed paths is a technique that warrants observation.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch external articles and download images for the blog. Specifically, scripts/import_article.py uses a platform-specific proxied_get and scripts/import_x_articles.py uses urllib.request.urlopen to retrieve remote assets. These operations target arbitrary domains provided by the user or found in data feeds.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 06:49 PM
Security Audit — agent-trust-hub — @1892/agent-blog