virality
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to search for and ingest content from X/Twitter and YouTube, creating an attack surface where instructions embedded in social media posts or metadata could influence the agent's behavior.\n
- Ingestion points: Untrusted external data is ingested via search results on X (Step 3) and YouTube (Step 4) as described in
references/virality-playbook.md.\n - Boundary markers: The prompts do not include delimiters or specific instructions to isolate or treat external content as untrusted data.\n
- Capability inventory: The agent uses network-connected tools (X and YouTube APIs) to retrieve data and produces local planning documents based on those inputs.\n
- Sanitization: No sanitization or validation of the retrieved external content is specified before the agent processes it.
Audit Metadata