@1892/agent-blog
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides tools to fetch content from external URLs (
scripts/import_article.py) and process external data feeds (scripts/import_x_articles.py) to generate blog posts. This represents an indirect prompt injection surface where a malicious external source could provide instructions designed to influence the agent's behavior when it later processes or summarizes the imported drafts. - Ingestion points: The URL argument in
scripts/import_article.pyand the JSON data source inscripts/import_x_articles.py. - Boundary markers: No explicit delimiters or warnings to ignore instructions within the imported content were identified.
- Capability inventory: The skill can perform network reads (
proxied_get,urllib.request.urlopen) and file writes across several scripts. - Sanitization: While the importer scopes CSS to prevent style leakage, it extracts and preserves inline script blocks and HTML text from the source without sanitizing them for prompt injection patterns.
- [DYNAMIC_EXECUTION]: The generator (
build.py) and the image generator (scripts/og_image.py) useimportlib.utilto dynamically load theconfig.pyfile from the project root. While this is a common pattern for local configuration in this type of project, dynamic loading from computed paths is a technique that warrants observation. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch external articles and download images for the blog. Specifically,
scripts/import_article.pyuses a platform-specificproxied_getandscripts/import_x_articles.pyusesurllib.request.urlopento retrieve remote assets. These operations target arbitrary domains provided by the user or found in data feeds.
Audit Metadata