social-media-api-integration

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture handles user-provided text for distribution to external social media APIs, which is a common surface for indirect prompt injection.
  • Ingestion points: The Post dataclass defined in SKILL.md captures arbitrary strings for title and body from user input or external sources.
  • Boundary markers: The code templates in SKILL.md do not implement specific boundary markers or instructions to isolate user data from agent instructions during processing.
  • Capability inventory: The skill utilizes httpx and authlib in SKILL.md to perform network operations, including posting data to external social media platform endpoints.
  • Sanitization: The implementation in SKILL.md includes length-based truncation (e.g., 300 or 500 characters) to meet platform constraints, but does not include structural sanitization or escaping of the user-provided text before transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — social-media-api-integration