technical-blog-writing

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a content creation workflow that ingests external data from web searches, establishing a surface for indirect prompt injection.
  • Ingestion points: Web research results from the exa/search tool mentioned in SKILL.md.
  • Boundary markers: Not specified in the provided workflow examples.
  • Capability inventory: The agent has access to Bash(belt *), a Python executor, and social media posting tools.
  • Sanitization: No sanitization or filtering of external data is implemented in the provided templates.
  • [EXTERNAL_DOWNLOADS]: Includes a reference to installation instructions hosted on the official inference-sh GitHub repository.
  • [COMMAND_EXECUTION]: Demonstrates use of the belt CLI to run helper applications for research and data visualization, including a Python-based chart generator.
  • [CREDENTIALS_UNSAFE]: References the belt login command, which is the standard, documented authentication process for the vendor's platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 02:47 AM