influencer-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of
yt-dlpviapip.yt-dlpis a well-known, legitimate, and widely-used open-source utility for interacting with social media media content. - [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection because it ingests and processes data from external social media platforms controlled by third parties.
- Ingestion points: Blogger profiles, bios, descriptions, and post content from Douyin, Xiaohongshu, and Bilibili are retrieved using the
browsertool (defined inSKILL.md). - Boundary markers: The instructions do not define any delimiters or explicit safety warnings to the agent to disregard instructions that might be embedded within the crawled profile information or video metadata.
- Capability inventory: The agent uses
browserfor web navigation,yt-dlpfor downloading content, andffmpegfor processing media files. - Sanitization: There is no evidence of sanitization, validation, or escaping of the retrieved external data before it is interpolated into the agent's context for AI analysis.
Audit Metadata