technical-blog-writing
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill defines a content creation workflow that ingests external data from web searches, establishing a surface for indirect prompt injection.
- Ingestion points: Web research results from the
exa/searchtool mentioned inSKILL.md. - Boundary markers: Not specified in the provided workflow examples.
- Capability inventory: The agent has access to
Bash(belt *), a Python executor, and social media posting tools. - Sanitization: No sanitization or filtering of external data is implemented in the provided templates.
- [EXTERNAL_DOWNLOADS]: Includes a reference to installation instructions hosted on the official
inference-shGitHub repository. - [COMMAND_EXECUTION]: Demonstrates use of the
beltCLI to run helper applications for research and data visualization, including a Python-based chart generator. - [CREDENTIALS_UNSAFE]: References the
belt logincommand, which is the standard, documented authentication process for the vendor's platform.
Audit Metadata