promote-post

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: The skill retrieves content from external URLs using WebFetch and reads local files using the Read tool (SKILL.md, Step 1).\n
  • Boundary markers: The instructions in SKILL.md do not define explicit delimiters or instructions to ignore potential commands embedded in the fetched article content.\n
  • Capability inventory: The skill's primary function is restricted to text generation; it explicitly prohibits automatic publishing of the generated tweets (SKILL.md, Critical Rules).\n
  • Sanitization: There is no mention of sanitizing or filtering the fetched content before analysis in SKILL.md.\n- [EXTERNAL_DOWNLOADS]: Fetches article content via the well-known Jina Reader service (r.jina.ai) to convert web pages into an LLM-friendly format for analysis (SKILL.md, Step 1).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:08 PM
Security Audit — agent-trust-hub — promote-post