publish-x-article

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions and referenced external tools send Markdown tables and Mermaid diagrams to an external third-party service (diagramless.xyz) via API to convert them into PNG images. This process involves transmitting user-provided document content to a remote server, which could lead to the exposure of sensitive information contained within the articles.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and adapts external Markdown files where malicious instructions could be embedded to influence the agent's behavior during the pre-processing phase.
  • Ingestion points: External Markdown files provided by the user and read via scripts like parse_markdown.py and cat commands.
  • Boundary markers: None identified; there are no specific instructions or delimiters used to separate the article data from the agent's core instructions.
  • Capability inventory: The skill possesses capabilities for browser automation (Playwright), file system read/write access, system clipboard manipulation, and network access (to X.com and diagramless.xyz).
  • Sanitization: No sanitization or safety checks are performed on the Markdown content before the agent is instructed to "Read the content" and "restructure" it.
  • [COMMAND_EXECUTION]: The skill relies on shell command execution (python, node, cat) with user-provided file paths to perform its core logic. While no explicit command injection vulnerability was found in the provided scripts, the architectural reliance on external shell calls for data processing increases the system's attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:41 AM
Security Audit — agent-trust-hub — publish-x-article