ai-content-pipeline-automation

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires cloning an external repository from GitHub (pennydinh/marketing-pineline-share) and running installation commands such as npm install or yarn install to fetch dependencies.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present due to the skill's automated workflow.
  • Ingestion points: The system crawls real-time data from external sources like Twitter, LinkedIn, and TechCrunch via the Research Module.
  • Boundary markers: There are no defined boundary markers or instructions to the AI to ignore potential commands embedded in the crawled web content.
  • Capability inventory: The skill generates text and video content which can then be automatically published to social media platforms (Facebook).
  • Sanitization: No input sanitization or validation mechanisms are described for the data fetched from external sources before it is passed to the LLM (Claude/OpenAI).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 12:57 AM
Security Audit — agent-trust-hub — ai-content-pipeline-automation