social-content

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions create a surface for indirect prompt injection. It directs the agent to ingest and analyze untrusted data from external sources, such as blog posts, podcasts, and videos for repurposing, as well as scraped social media content for competitive analysis. There are no instructions for the agent to use boundary markers or to disregard instructions potentially embedded within this source material.
  • Ingestion points: SKILL.md (under 'Content Repurposing System' and 'Reverse Engineering Viral Content').
  • Boundary markers: Absent; the skill does not instruct the agent to use delimiters or to ignore commands within the source text.
  • Capability inventory: The agent is prompted to perform data extraction and content generation based on these external inputs.
  • Sanitization: Absent; no input validation or content filtering is specified.
  • [SAFE]: No evidence of malicious behavior such as hardcoded credentials, unauthorized network exfiltration, or persistence mechanisms was detected. The skill consists entirely of instructional text and markdown templates.
  • [SAFE]: The findings related to 'external commands' and 'system reconnaissance' mentioned in the accompanying metadata report were reviewed and determined to be false positives. These detections occurred on markdown code fences used for post templates and analytics checklists, which do not involve executable command invocation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 06:09 PM
Security Audit — agent-trust-hub — social-content