technical-blog-writing
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bash(infsh *)tool to perform CLI operations likeinfsh loginand executing various utility apps.\n- [REMOTE_CODE_EXECUTION]: Theinfsh/python-executortool is used to execute a Python script for chart generation. This represents a pattern of script generation and execution through a remote tool.\n- [EXTERNAL_DOWNLOADS]: Instructions include installing additional agent skills from theinference-sh/skillsrepository usingnpx.\n- [PROMPT_INJECTION]: The skill processes external search data from theexa/searchtool. While this creates an ingestion point for untrusted instructions, the risk is minimal given the focused task of blog writing.
Audit Metadata