blog-calendar
Pass
Audited by Gen Agent Trust Hub on Feb 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface.
- Ingestion points: The skill scans and reads local files with .md, .mdx, and .html extensions to gather context and detect content decay (SKILL.md, Steps 1 and 2.5).
- Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore embedded commands within the blog files it processes.
- Capability inventory: The skill generates structured editorial calendars and suggests the execution of subsequent tools or commands such as '$blog write' and '$blog rewrite'.
- Sanitization: No mechanisms for sanitizing or validating the content extracted from the local files are described.
Audit Metadata