streaming-recommendations

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill's instructions are focused entirely on providing media recommendations. No markers for safety bypass, role-play injection, or system prompt extraction were found.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file paths (e.g., .ssh, .aws), or unauthorized network exfiltration attempts were detected. The skill uses standard web search tools to fetch public entertainment data.\n- [OBFUSCATION]: No Base64, hex encoding, zero-width characters, or homoglyph substitutions were used to hide content or commands.\n- [REMOTE_CODE_EXECUTION]: No patterns involving the download or execution of remote scripts or packages (e.g., curl|bash) were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a minimal attack surface by ingesting user preferences and web search results, but lacks the high-privilege capabilities required for exploitation.\n
  • Ingestion points: User-defined dimensions (genre, mood, platform) and external web search results in SKILL.md.\n
  • Boundary markers: None used to separate external data from internal logic.\n
  • Capability inventory: Limited to the web search tool; no file system or system command execution detected.\n
  • Sanitization: None performed on external content.\n- [DYNAMIC_CONTEXT_INJECTION]: No shell command interpolation placeholders (!command) were found in any of the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:55 AM
Security Audit — agent-trust-hub — streaming-recommendations