discovering-brand-ambassadors-across-platforms

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_&_EXFILTRATION]: The skill uses the APIFY_TOKEN environment variable for authentication, which is a standard and secure practice for managing API credentials. It provides instructions to set this in the environment or a .env file rather than hardcoding values.
  • [EXTERNAL_DOWNLOADS]: The skill references Apify actors (apidojo/instagram-scraper, etc.) and the Apify API (api.apify.com). These are well-known services used for their intended purpose in this context.
  • [COMMAND_EXECUTION]: The skill provides example curl commands and a reference to a run_actor.js script to interact with the Apify API. These commands are transparent, for the user to execute, and serve the primary purpose of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (social media profiles). While this presents a surface for indirect prompt injection, the risk is low as the data is used for metric calculation and classification rather than as direct instructions for the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 06:37 PM
Security Audit — agent-trust-hub — discovering-brand-ambassadors-across-platforms