blog-calendar

Pass

Audited by Gen Agent Trust Hub on Feb 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface.
  • Ingestion points: The skill scans and reads local files with .md, .mdx, and .html extensions to gather context and detect content decay (SKILL.md, Steps 1 and 2.5).
  • Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore embedded commands within the blog files it processes.
  • Capability inventory: The skill generates structured editorial calendars and suggests the execution of subsequent tools or commands such as '$blog write' and '$blog rewrite'.
  • Sanitization: No mechanisms for sanitizing or validating the content extracted from the local files are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 26, 2026, 01:29 AM