streaming-recommendations
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill's instructions are focused entirely on providing media recommendations. No markers for safety bypass, role-play injection, or system prompt extraction were found.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file paths (e.g., .ssh, .aws), or unauthorized network exfiltration attempts were detected. The skill uses standard web search tools to fetch public entertainment data.\n- [OBFUSCATION]: No Base64, hex encoding, zero-width characters, or homoglyph substitutions were used to hide content or commands.\n- [REMOTE_CODE_EXECUTION]: No patterns involving the download or execution of remote scripts or packages (e.g., curl|bash) were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a minimal attack surface by ingesting user preferences and web search results, but lacks the high-privilege capabilities required for exploitation.\n
- Ingestion points: User-defined dimensions (genre, mood, platform) and external web search results in
SKILL.md.\n - Boundary markers: None used to separate external data from internal logic.\n
- Capability inventory: Limited to the web search tool; no file system or system command execution detected.\n
- Sanitization: None performed on external content.\n- [DYNAMIC_CONTEXT_INJECTION]: No shell command interpolation placeholders (
!command) were found in any of the skill files.
Audit Metadata