bundle-social-accounts

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, such as prompt injection, unauthorized data access, or remote code execution, were detected across the skill files.
  • [CREDENTIALS_UNSAFE]: The skill correctly uses placeholders like <your-api-key> in documentation and examples. It contains a critical instruction for the AI agent: "NEVER call the API — you won't have credentials," which mitigates the risk of the agent attempting unauthorized operations or leaking credentials.
  • [PROMPT_INJECTION]: The instructions are purely functional and do not attempt to override the agent's safety protocols or system prompts.
  • [DATA_EXFILTRATION]: No patterns of data exfiltration were found. The skill only references the legitimate API endpoint https://api.bundle.social for documentation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:34 AM