publisher-codex

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from several external directories, representing an ingestion surface for content that could contain malicious instructions.\n
  • Ingestion points: Reads files from outputs/captions/, outputs/creatives/, outputs/linkedin/, outputs/threads/, outputs/x/, context/content-calendar.md, and context/compliance-rules.md.\n
  • Boundary markers: The instructions lack explicit requirements for using delimiters or boundary markers to isolate ingested content from the agent's instructions.\n
  • Capability inventory: The skill is capable of generating Markdown publishing plans and preparing Blotato API payloads; it requires explicit user confirmation before any publishing or scheduling occurs.\n
  • Sanitization: There are no instructions for sanitizing or validating the content of the ingested files before they are interpolated into the output payloads.\n- [SAFE]: The skill includes explicit security guidelines to protect credentials, instructing the user and agent to use environment variables and avoid hardcoding or committing API keys to the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:59 AM
Security Audit — agent-trust-hub — publisher-codex